Vulnerability Name: | CVE-2007-1169 (CCN-32876) | ||||||||
Assigned: | 2007-02-16 | ||||||||
Published: | 2007-02-16 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | The web interface in Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 accepts logon requests through unencrypted HTTP, which might allow remote attackers to obtain credentials by sniffing the network. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1169 Source: CCN Type: Trend Micro Web site ServerProtect for Linux Source: CONFIRM Type: Patch http://www.trendmicro.com/download/product.asp?productid=20 Source: XF Type: UNKNOWN splx-web-interface-info-disclosure(32876) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |