CVE-2020-8604: Trend Micro InterScan Web Security Virtual Appliance Apache Solr Directory Traversal Information Disclosure Vulnerability
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro InterScan Web Security Virtual Appliance. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Apache Solr application. When parsing the file parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of IWSS user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8604?
The severity of CVE-2020-8604 is high with a severity value of 7.5.
What is the vulnerability described in CVE-2020-8604?
CVE-2020-8604 is a vulnerability that allows remote attackers to disclose sensitive information on affected installations of Trend Micro InterScan Web Security Virtual Appliance.
Is authentication required to exploit CVE-2020-8604?
No, authentication is not required to exploit CVE-2020-8604.
How can I fix CVE-2020-8604?
To fix CVE-2020-8604, it is recommended to apply the necessary security updates or patches provided by Trend Micro.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-8604?
The Common Weakness Enumeration (CWE) ID for CVE-2020-8604 is CWE-22.