CVE Vulnerabilities

CVE-2019-9488

Improper Restriction of XML External Entity Reference

Published: Sep 11, 2019 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
Deep_security_managerTrendmicro10.0 (including)10.0 (including)
Deep_security_managerTrendmicro10.0-u1 (including)10.0-u1 (including)
Deep_security_managerTrendmicro10.0-u10 (including)10.0-u10 (including)
Deep_security_managerTrendmicro10.0-u11 (including)10.0-u11 (including)
Deep_security_managerTrendmicro10.0-u12 (including)10.0-u12 (including)
Deep_security_managerTrendmicro10.0-u13 (including)10.0-u13 (including)
Deep_security_managerTrendmicro10.0-u14 (including)10.0-u14 (including)
Deep_security_managerTrendmicro10.0-u15 (including)10.0-u15 (including)
Deep_security_managerTrendmicro10.0-u16 (including)10.0-u16 (including)
Deep_security_managerTrendmicro10.0-u17 (including)10.0-u17 (including)
Deep_security_managerTrendmicro10.0-u18 (including)10.0-u18 (including)
Deep_security_managerTrendmicro10.0-u19 (including)10.0-u19 (including)
Deep_security_managerTrendmicro10.0-u2 (including)10.0-u2 (including)
Deep_security_managerTrendmicro10.0-u3 (including)10.0-u3 (including)
Deep_security_managerTrendmicro10.0-u4 (including)10.0-u4 (including)
Deep_security_managerTrendmicro10.0-u5 (including)10.0-u5 (including)
Deep_security_managerTrendmicro10.0-u6 (including)10.0-u6 (including)
Deep_security_managerTrendmicro10.0-u7 (including)10.0-u7 (including)
Deep_security_managerTrendmicro10.0-u8 (including)10.0-u8 (including)
Deep_security_managerTrendmicro10.0-u9 (including)10.0-u9 (including)
Deep_security_managerTrendmicro11.0 (including)11.0 (including)
Deep_security_managerTrendmicro11.0-u1 (including)11.0-u1 (including)
Deep_security_managerTrendmicro11.0-u2 (including)11.0-u2 (including)
Deep_security_managerTrendmicro11.0-u3 (including)11.0-u3 (including)
Deep_security_managerTrendmicro11.0-u4 (including)11.0-u4 (including)
Deep_security_managerTrendmicro11.0-u5 (including)11.0-u5 (including)
Deep_security_managerTrendmicro11.0-u6 (including)11.0-u6 (including)
Deep_security_managerTrendmicro11.0-u7 (including)11.0-u7 (including)
Deep_security_managerTrendmicro11.3 (including)11.3 (including)
Vulnerability_protectionTrendmicro2.0 (including)2.0 (including)

Potential Mitigations

References