A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's web management interface.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-21-525/ | Third Party Advisory VDB Entry | 
| https://success.trendmicro.com/solution/000286439 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2021-05-10 04:15
Updated : 2021-05-19 11:25
NVD link : CVE-2021-31520
Mitre link : CVE-2021-31520
JSON object : View
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
Products Affected
                trendmicro
- im_security
 


