CVE-2016-8589: Critical severity trend micro threat discovery appliance vulnerability
logquerydae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cacheid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8589?
CVE-2016-8589 is considered to have a high severity due to the potential for remote code execution as the root user.
How do I fix CVE-2016-8589?
To fix CVE-2016-8589, update Trend Micro Threat Discovery Appliance to version 2.6.1063 or later.
What are the consequences of exploiting CVE-2016-8589?
Exploiting CVE-2016-8589 allows remote authenticated users to execute arbitrary code on the vulnerable system with root privileges.
Who is affected by CVE-2016-8589?
Users of Trend Micro Threat Discovery Appliance versions 2.6.1062r1 and earlier are affected by CVE-2016-8589.
What type of vulnerabilities does CVE-2016-8589 represent?
CVE-2016-8589 represents a remote code execution vulnerability caused by improper input validation in a web application.