Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Cross-Site Request Forgery (CSRF) vulnerabilities in Deep Discovery Inspector (DDI)

    • Updated:
    • 25 Mar 2016
    • Product/Version:
    • Deep Discovery Inspector 3.7
    • Deep Discovery Inspector 3.8
    • Platform:
    • N/A N/A
Summary

Trend Micro has received reports that DDI is affected by CSRF vulnerabilities. These affect the following console features:

  • Deny List Notifications
  • Detection Rules
  • Threat Detections
  • Email Settings
  • Network
  • Blacklisting/Whitelisting
  • Time
  • Accounts
  • Power Off / Restart
Details
Public

The following DDI versions prior to version 3.8 Service Pack 2 (SP2) are affected:

  • 3.8 English 
  • 3.8 Japanese
  • 3.7 English
  • 3.7 Japanese
  • 3.7 Simplified Chinese

Trend Micro has released DDI 3.8 SP2. All versions up to version 3.8 SP1 must upgrade to version 3.8 SP2 (Build 3.82.1133) to address this issue.

The DDI 3.8 SP2 upgrade can also be downloaded from the Trend Micro Download Center.

Trend Micro would also like to thank John Page (hyp3rlinx.altervista.org) for the responsible disclosure of the issues addressed in this advisory.

Premium
Internal
Rating:
Category:
Configure; Troubleshoot; SPEC
Solution Id:
1113708
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.