Lucene search

K
cveMitreCVE-2009-0613
HistoryFeb 17, 2009 - 5:30 p.m.

CVE-2009-0613

2009-02-1717:30:06
CWE-264
mitre
web.nvd.nist.gov
24
cve-2009-0613
trend micro
iwss
security
bypass
permission
configuration
auditor
report only

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

61.6%

Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.

Affected configurations

Nvd
Node
trendmicrointerscan_web_security_suiteMatch3.1
VendorProductVersionCPE
trendmicrointerscan_web_security_suite3.1cpe:2.3:a:trendmicro:interscan_web_security_suite:3.1:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

61.6%

Related for CVE-2009-0613