PT-2017-11976 · Trend Micro · Trend Micro Control Manager

Published

2017-07-31

·

Updated

2017-08-04

·

CVE-2017-11390

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Control Manager version 6.0
Description The issue is related to XML external entity (XXE) processing, which could lead to information disclosure if exploited.
Recommendations For Trend Micro Control Manager version 6.0, update to a version that fixes the XML external entity processing vulnerability to prevent information disclosure.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11390
ZDI-17-501

Affected Products

Trend Micro Control Manager