VulnerabilityModified
CVE-2009-0613
Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.
MEDIUM 6.0EPSS 1.50%
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- trendmicro/interscan web security suite
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33867Vendor Advisory
- http://www.securitytracker.com/id?1021694
- http://www.trendmicro.com/ftp/documentation/readme/iwss_31_win_en_readme_CP_1237_EN.txtVendor Advisory
- http://www.vupen.com/english/advisories/2009/0369
- http://secunia.com/advisories/33867Vendor Advisory
- http://www.securitytracker.com/id?1021694
- http://www.trendmicro.com/ftp/documentation/readme/iwss_31_win_en_readme_CP_1237_EN.txtVendor Advisory
- http://www.vupen.com/english/advisories/2009/0369
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.