VYPR
Unrated severityNVD Advisory· Published Feb 17, 2009· Updated Jun 16, 2026

CVE-2009-0612

CVE-2009-0612

Description

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

Affected products

5
  • cpe:2.3:a:trendmicro:interscan_web_security_suite:2.5:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:trendmicro:interscan_web_security_suite:2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:trendmicro:interscan_web_security_suite:3.1:*:*:*:*:*:*:*
    • (no CPE)range: 3.x
  • cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:3.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:3.1:*:*:*:*:*:*:*
    • (no CPE)range: 3.x

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.