Security Advisory

CVE-2009-0612

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-02-17 17:00:00
Last updated 2024-08-07 04:40:05
Assigner mitre
State PUBLISHED

Description

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.