Trend Micro Security

LANDESK Management Suite Cross-Site Scripting Security Vulnerability

  危険度: : 緊急
  CVE識別番号: CVE-2014-5360

  概要

Cross-site scripting (XSS) vulnerability in the admin interface in LANDESK Management Suite before 9.6 SP1 allows remote attackers to inject arbitrary web script or HTML via the AMTVersion parameter to remote/serverlist_grouptree.aspx.

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1000552
  Trend Micro Deep Security DPI Rule Name: 1000552 - Generic Cross Site Scripting(XSS) Prevention

  影響を受けるソフトウェア

  • Landesk Management Suite