RULE(RULE ID:317404)

Rule General Information
Release Date: 2017-05-05
Rule Name: WEB-OTHER Trend Micro Control Manager ProductTree_RightWindow XML External Entity Processing (ZDI-17-077)
Severity:
CVE ID:
Rule Protection Details
Description: An XML external entity (XXE) processing vulnerability has been reported in Trend Micro Control Manager. The vulnerability is due to lack of validation of user-supplied input prior to executing an XML query in ProductTree_RightWindow.aspx.
Impact: Information disclosure
Affected OS: Windows
Reference: ZeroDayInitiative:ZDI-17-077
Solutions
Update vendor's patch.