First published: Thu Oct 17 2019(Updated: )
The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Deep Security | =10.0 | |
Trendmicro Deep Security | =11.0 | |
Trendmicro Deep Security | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-15626.
The severity of CVE-2019-15626 is high with a CVSS score of 7.5.
Versions 10.0, 11.0, and 12.0 of the Deep Security Manager application are affected.
CVE-2019-15626 may result in confidentiality impact as initial LDAP communication may be transmitted in clear text.
To fix CVE-2019-15626, update your Deep Security Manager application to a version that addresses this vulnerability.