CVE-2015-2873: Medium severity trend micro deep discovery inspector vulnerability
Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the configuration via a direct request to the (1) system log URL, (2) whitelist URL, or (3) blacklist URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2873?
CVE-2015-2873 has a medium severity rating, indicating a moderate impact on security.
How do I fix CVE-2015-2873?
To fix CVE-2015-2873, upgrade to the latest version of Trend Micro Deep Discovery Inspector as specified in the vulnerability announcements.
What versions are affected by CVE-2015-2873?
CVE-2015-2873 affects Trend Micro Deep Discovery Inspector versions prior to 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, and 3.8.x before 3.8.1263.
What kind of attacks does CVE-2015-2873 enable?
CVE-2015-2873 allows remote attackers to obtain sensitive information or change configurations via direct requests.
Is there a workaround for CVE-2015-2873?
There are no official workarounds for CVE-2015-2873, and upgrading to a patched version is the recommended action.