Trend Micro InterScan Web Security Virtual Appliance Flaws Let Local Users Gain Elevated Privileges and Remote Users Upload/Download Arbitrary Files
|
|
SecurityTracker Alert ID: 1024153 |
|
SecurityTracker URL: http://securitytracker.com/id?1024153
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jun 24 2010
|
Impact:
Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information, User access via local system
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): Appliance version 5.0
|
Description:
Several vulnerabilities were reported in InterScan Web Security Virtual Appliance. A local user can obtain elevated privileges on the target system. A remote authenticated user can upload and download arbitrary files to/from the target system.
A local user can invoke the '/usr/iwss/AdminUi/uihelper' shell to execute arbitrary commands on the target system with elevated privileges.
The software does not properly validate user-supplied input. A remote authenticated user can supply a specially crafted request via the CA import function to upload files to arbitrary locations on the target system. The vulnerability resides in the 'com.trend.iwss.gui.servlet.XMLRPCcert' servlet in the 'filename' parameter.
A remote authenticated user can supply a specially crafted request to download files from arbitrary locations on the target system. The vulnerability resides in the 'com.trend.iwss.gui.servlet.ConfigBackup' servlet in the 'pkg_name' parameter and in the 'com.trend.iwss.gui.servlet.exportreport' servlet in the 'exportname' parameter.
The vendor was notified on April 9, 2010.
Ivan Huertas from CYBSEC S.A. reported these vulnerabilities.
|
Impact:
A local user can obtain elevated privileges on the target system.
A remote user can upload files to the target system.
A remote user can download files from the target system.
|
Solution:
The vendor has issued a patch, available at:
http://downloadcenter.trendmicro.com/index.php?clk=tbl&clkval=249®s=NABU&lang_loc=1
The vendor's advisory is available at:
http://www.trendmicro.com/ftp/documentation/readme/iwsva_50_ar64_en_cp1386_readme.txt
|
Vendor URL: www.trendmicro.com/ (Links to External Site)
|
Cause:
Access control error, Input validation error
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|