CVE-2009-0612
Last modified
CVE-2009-0612 is a vulnerability of currently unknown severity. Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Interscan Web Security Suite | 2.5 |
| Trendmicro | Interscan Web Security Suite | 3.1 |
| Trendmicro | Interscan Web Security Virtual Appliance | 3.1 |
References
- http://secunia.com/advisories/33891Vendor Advisory
- http://secunia.com/advisories/33891Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0612?
How severe is CVE-2009-0612?
How do I fix CVE-2009-0612?
Are you affected by CVE-2009-0612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
