2019-09-11 20:15:10 2019-09-13 23:11:22

Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).

Vector

NETWORK

Complexity

LOW

Authentication

SINGLE_INSTANCE

Confidentiality

PARTIAL

Integrity

NONE

Availability

NONE
Trendmicro Deep security manager 10.0 - (not an official CPE) Trendmicro Deep security manager 10.0 U1 (not an official CPE) Trendmicro Deep security manager 10.0 U10 (not an official CPE) Trendmicro Deep security manager 10.0 U11 (not an official CPE) Trendmicro Deep security manager 10.0 U12 (not an official CPE) Trendmicro Deep security manager 10.0 U13 (not an official CPE) Trendmicro Deep security manager 10.0 U14 (not an official CPE) Trendmicro Deep security manager 10.0 U15 (not an official CPE) Trendmicro Deep security manager 10.0 U16 (not an official CPE) Trendmicro Deep security manager 10.0 U17 (not an official CPE) Trendmicro Deep security manager 10.0 U18 (not an official CPE) Trendmicro Deep security manager 10.0 U19 (not an official CPE) Trendmicro Deep security manager 10.0 U2 (not an official CPE) Trendmicro Deep security manager 10.0 U3 (not an official CPE) Trendmicro Deep security manager 10.0 U4 (not an official CPE) Trendmicro Deep security manager 10.0 U5 (not an official CPE) Trendmicro Deep security manager 10.0 U6 (not an official CPE) Trendmicro Deep security manager 10.0 U7 (not an official CPE) Trendmicro Deep security manager 10.0 U8 (not an official CPE) Trendmicro Deep security manager 10.0 U9 (not an official CPE) Trendmicro Deep security manager 11.0 - (not an official CPE) Trendmicro Deep security manager 11.0 U1 (not an official CPE) Trendmicro Deep security manager 11.0 U2 (not an official CPE) Trendmicro Deep security manager 11.0 U3 (not an official CPE) Trendmicro Deep security manager 11.0 U4 (not an official CPE) Trendmicro Deep security manager 11.0 U5 (not an official CPE) Trendmicro Deep security manager 11.0 U6 (not an official CPE) Trendmicro Deep security manager 11.0 U7 (not an official CPE) Trendmicro Deep security manager 11.3 - (not an official CPE) Trendmicro Vulnerability protection 2.0 - (not an official CPE)
Advisory Patch Confirmed Link
N/A