ID

VAR-201103-0376


TITLE

Trend Micro WebReputation API URI Security Bypass Vulnerability

Trust: 1.1

sources: IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1091 // BID: 46864

DESCRIPTION

Trend Micro WebReputation API technology can be used to prevent clients from accessing suspicious web sites. The Trend Micro WebReputation API has a security bypass vulnerability that allows an attacker to bypass the filters contained in the download mechanism and successfully exploit the vulnerability to allow target users to download malicious files to the system. Trend Micro WebReputation API is prone to a security-bypass vulnerability. Successful exploits may cause victims to download malicious files onto affected computers. This issue affects WebReputation API 10.5; other versions may also be vulnerable

Trust: 0.99

sources: CNVD: CNVD-2011-1091 // BID: 46864 // IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1091

AFFECTED PRODUCTS

vendor:trend micromodel:webreputation apiscope:eqversion:10.5

Trust: 1.1

vendor:trend micromodel:webreputation apiscope:eqversion:0

Trust: 0.3

sources: IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1091 // BID: 46864

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 46864

TYPE

Design Error

Trust: 0.3

sources: BID: 46864

PATCH

title:Trend Micro WebReputation API URI security bypass vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/3295

Trust: 0.6

sources: CNVD: CNVD-2011-1091

EXTERNAL IDS

db:BIDid:46864

Trust: 0.9

db:CNVDid:CNVD-2011-1091

Trust: 0.8

db:IVDid:0140BA60-1F9C-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 0140ba60-1f9c-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1091 // BID: 46864

REFERENCES

url:http://www.securityfocus.com/bid/46864/

Trust: 0.6

url:http://www.trend.com

Trust: 0.3

sources: CNVD: CNVD-2011-1091 // BID: 46864

CREDITS

DcLabs Security Research Group

Trust: 0.3

sources: BID: 46864

SOURCES

db:IVDid:0140ba60-1f9c-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-1091
db:BIDid:46864

LAST UPDATE DATE

2022-05-17T02:10:48.102000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-1091date:2011-03-15T00:00:00
db:BIDid:46864date:2011-03-14T00:00:00

SOURCES RELEASE DATE

db:IVDid:0140ba60-1f9c-11e6-abef-000c29c66e3ddate:2011-03-15T00:00:00
db:CNVDid:CNVD-2011-1091date:2011-03-15T00:00:00
db:BIDid:46864date:2011-03-14T00:00:00