Security Advisory

CVE-2016-7552

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-04-12 10:00:00
Last updated 2024-08-06 02:04:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.