PT-2022-15862 · Trend Micro · Deep Security Manager+2

Carl Fabian Luepke

+1

·

Published

2022-01-20

·

Updated

2022-02-03

·

CVE-2022-23119

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux versions 20 and below
Description A directory traversal issue could allow an attacker to read arbitrary files from the file system. The attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this issue.
Recommendations For versions 20 and below, ensure the Deep Security Manager (DSM) and agents are properly secured and configured to prevent unauthorized access. As a temporary workaround, consider restricting access to sensitive files and directories until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23119

Affected Products

Cloud One - Workload Security Agent For Linux
Deep Security Manager
Trend Micro Deep Security