XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.
2022-11-04T12:15:15.377
2024-11-21T07:19:19.833
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trellix | intrusion_prevention_system_manager | < 10.1 | Yes |
Application | trellix | intrusion_prevention_system_manager | 10.1 | Yes |
Application | trellix | intrusion_prevention_system_manager | 10.1 | Yes |