CVE-2016-3987: Critical severity trendmicro Password Manager vulnerability
Published Apr 8, 2016
·Updated
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
Affected Software
1 affected component
trendmicro Password Manager
Event History
Apr 8, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3987?
CVE-2016-3987 is rated as a critical vulnerability due to its ability to allow remote command execution.
2
How do I fix CVE-2016-3987?
To mitigate CVE-2016-3987, update the Trend Micro Password Manager to the latest version that addresses this issue.
3
What are the potential impacts of CVE-2016-3987?
CVE-2016-3987 can lead to unauthorized execution of commands on the server, resulting in a complete system compromise.
4
Which software is affected by CVE-2016-3987?
CVE-2016-3987 affects all versions of Trend Micro Password Manager.
5
Is CVE-2016-3987 being actively exploited?
As of the last reports, CVE-2016-3987 is considered to be actively targeted in the wild.