SB2014110701 - Input validation error in InterScan Web Security Virtual Appliance
Published: November 7, 2014 Updated: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2014-8510)
The vulnerability allows a remote #AU# to gain access to sensitive information.
The AdminUI in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) before 6.0 HF build 1244 allows remote authenticated users to read arbitrary files via vectors related to configuration input when saving filters.
Remediation
Install update from vendor's website.