PT-2022-15862 · Trend Micro · Deep Security Manager+2
Carl Fabian Luepke
+1
·
Published
2022-01-20
·
Updated
2022-02-03
·
CVE-2022-23119
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux versions 20 and below
Description
A directory traversal issue could allow an attacker to read arbitrary files from the file system. The attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this issue.
Recommendations
For versions 20 and below, ensure the Deep Security Manager (DSM) and agents are properly secured and configured to prevent unauthorized access. As a temporary workaround, consider restricting access to sensitive files and directories until a patch is available.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud One - Workload Security Agent For Linux
Deep Security Manager
Trend Micro Deep Security