Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-19541 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2024-08-04T16:03:23.261Z
Reserved: 2020-10-12T00:00:00
Link: CVE-2020-27017
No data.
Status : Modified
Published: 2020-11-09T23:15:12.147
Modified: 2024-11-21T05:20:41.063
Link: CVE-2020-27017
No data.
OpenCVE Enrichment
No data.
EUVD