PT-2017-10036 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance

Published

2017-02-21

·

Updated

2017-07-25

·

CVE-2016-9269

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Interscan Web Security Virtual Appliance (IWSVA) versions 6.5-SP2 Build Linux 1707 and earlier
Description The issue allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality in the com.trend.iwss.gui.servlet.ManagePatches component.
Recommendations For versions 6.5-SP2 Build Linux 1707 and earlier, update to Version 6.5 CP 1737 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9269

Affected Products

Trend Micro Interscan Web Security Virtual Appliance