[Japanese]

JVNDB-2023-003757

Trend Micro Mobile Security vulnerable to cross-site scripting

Overview

Trend Micro Incorporated has released a security update for Trend Micro Mobile Security.

Trend Micro Incorporated reported this vulnerability to JPCERT/CC to notify users of the solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.1 (Medium) [NVD Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: None
Affected Products


Trend Micro, Inc.
  • Trend Micro Mobile Security (Enterprise) 9.8

Impact

A cross-site scripting attack may be conducted if a user who is logged in to the product's management console accesses a link that contains a malicious script.
For more information, refer to the information provided by the developer.
Solution

[Apply the Patch]

Apply the patch according to the information provided by the developer.
The developer has released a patch below that contains a fix for this vulnerability.

* Mobile Security (Enterprise) 9.8 SP5 CP6 (b3311)
Vendor Information

Trend Micro, Inc.
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [NVD Evaluation]
CVE (What is CVE?)

  1. CVE-2023-41176
  2. CVE-2023-41177
  3. CVE-2023-41178
References

  1. JVN : JVNVU#95732401
  2. National Vulnerability Database (NVD) : CVE-2023-41176
  3. National Vulnerability Database (NVD) : CVE-2023-41177
  4. National Vulnerability Database (NVD) : CVE-2023-41178
Revision History

  • [2023/09/26]
      Web page was published
  • [2024/03/13]
      CVSS Severity was modified
      CWE was modified
      References : Contents were added