CVE-2019-9488: XEE
Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9488?
CVE-2019-9488 is classified as a critical severity vulnerability that can enable an XML External Entity Attack.
How do I fix CVE-2019-9488?
To remediate CVE-2019-9488, you must update Trend Micro Deep Security Manager and Vulnerability Protection to the latest patched versions.
Which versions of Trend Micro software are affected by CVE-2019-9488?
CVE-2019-9488 affects Trend Micro Deep Security Manager versions 10.x and 11.x, and Vulnerability Protection version 2.0.
Can the XML External Entity Attack be executed remotely in CVE-2019-9488?
For an XML External Entity Attack related to CVE-2019-9488 to succeed, the attacker must have root or admin access to the protected host.
What type of attack does CVE-2019-9488 involve?
CVE-2019-9488 involves an XML External Entity Attack that can potentially expose sensitive information.