Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arbitrary code with root privileges via a Trojan horse .war file in the Solr webapps directory.
References
Link | Resource |
---|---|
https://success.trendmicro.com/solution/1114913 | Mitigation Patch Vendor Advisory |
https://qkaiser.github.io/pentesting/trendmicro/2016/08/08/trendmicro-sps/ | Exploit Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-01-30 14:59
Updated : 2021-09-09 10:47
NVD link : CVE-2016-6268
Mitre link : CVE-2016-6268
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
trendmicro
- smart_protection_server