CVE-2009-0613: Medium severity trendmicro Interscan Web Security Suite vulnerability
Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trend Micro InterScan Web Security Suite (IWSS) 3.1to a version that resolves this vulnerability.Fixed in build 1237
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0613?
CVE-2009-0613 has been assigned a moderate severity due to its potential for privilege escalation.
Who is affected by CVE-2009-0613?
CVE-2009-0613 affects users of Trend Micro InterScan Web Security Suite 3.1 before build 1237.
How do I fix CVE-2009-0613?
To fix CVE-2009-0613, upgrade to Trend Micro InterScan Web Security Suite build 1237 or later.
What types of users can exploit CVE-2009-0613?
Remote authenticated Auditor and Report Only users can exploit CVE-2009-0613 to bypass permission settings.
What actions can be taken by exploiting CVE-2009-0613?
Exploitation of CVE-2009-0613 allows unauthorized modifications to the system configuration via certain JSP pages.