CVE-2009-0612
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows…
Does this matter?
Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.
Description
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 2.17% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- trendmicro/interscan web security suite · trendmicro/interscan web security virtual appliance
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33891Vendor Advisory
- http://www.securityfocus.com/archive/1/500760/100/0/threaded
- http://www.securityfocus.com/bid/33687
- http://www.securitytracker.com/id?1021716
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48681
- http://secunia.com/advisories/33891Vendor Advisory
- http://www.securityfocus.com/archive/1/500760/100/0/threaded
- http://www.securityfocus.com/bid/33687
- http://www.securitytracker.com/id?1021716
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48681
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.