Critical patch available for SQL injection attacks in Control Manager (TMCM)

Support
Solution ID Last Updated
1061043 Date : 2013/05/07 Time:7:53 AM , (PST)


Product/Version Platform
Control Manager - 5.0, 5.5, 6.0;
Windows - 2000 Advanced Server, 2000 Server, 2003 Enterprise, 2003 Server R2, 2003 Standard, 2008 Enterprise, 2008 Enterprise 64-bit, 2008 Server R2, 2008 Standard, 2008 Standard 64-bit

Problem Description

Trend Micro has been notified of a potential product vulnerability in TMCM.
First reported by CERT, the report says that the vulnerbaility enables SQL injection attacks, allowing remote attackers to execute SQL commands to upload and execute arbitrary code that may harm the target system.

Solution

Trend Micro has confirmed that this is a product vulnerability and impacts TMCM 6.0 and other versions.
Trend Micro filters user-supplied inputs to make sure all strings does not contain any damage commands before execution.
Critical patches for this vulnerability are now available:
TMCM 5.0
TMCM 5.5
TMCM 6.0


Rate this Solution
Did this article help you?

Please provide your comments to help us improve this solution.

 
  *This form is an automated system. General questions, technical, sales and product-related issues submitted through this form will not be answered.
 
 

Connect with us on