CVE-2016-4351: SQL Injection
Published May 5, 2016
·Updated
SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
1 affected component
trendmicro Email Encryption Gateway<=5.5
Event History
May 5, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4351?
CVE-2016-4351 is considered a critical vulnerability due to its potential for remote code execution through SQL injection.
2
How do I fix CVE-2016-4351?
To fix CVE-2016-4351, upgrade Trend Micro Email Encryption Gateway to version 5.5 build 1108 or later.
3
What software is affected by CVE-2016-4351?
CVE-2016-4351 affects Trend Micro Email Encryption Gateway versions prior to 5.5 build 1108.
4
Can CVE-2016-4351 be exploited remotely?
Yes, CVE-2016-4351 can be exploited remotely by attackers using SQL injection techniques.
5
What happens if CVE-2016-4351 is exploited?
If CVE-2016-4351 is exploited, attackers can execute arbitrary SQL commands which may compromise the database integrity.