The web interface in Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 prior to 20070216 accepts logon requests through unencrypted HTTP, which might allow remote malicious users to obtain credentials by sniffing the network.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
trend micro serverprotect 1.25_2007-02-16 |