PT-2018-9838 · Trend Micro · Trend Micro Email Encryption Gateway
Mr_Me
+1
·
Published
2018-05-04
·
Updated
2018-06-22
·
CVE-2018-10352
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Trend Micro Email Encryption Gateway version 5.5
Description:
A flaw in the formConfiguration class could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations. Authentication is required to exploit this issue.
Recommendations:
For Trend Micro Email Encryption Gateway version 5.5, consider restricting access to the formConfiguration class until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Email Encryption Gateway