CVE-2017-11390: XEE
Published Aug 2, 2017
·Updated
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.
Affected Software
1 affected component
trendmicro Control Manager=6.0
Remediation
Patch Available
Event History
Aug 2, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11390?
CVE-2017-11390 is rated as medium severity due to its potential for information disclosure.
2
How do I fix CVE-2017-11390?
To mitigate CVE-2017-11390, update Trend Micro Control Manager to a version that addresses the XML external entity processing vulnerability.
3
What is an XML external entity (XXE) vulnerability as referenced in CVE-2017-11390?
An XML external entity vulnerability allows attackers to interfere with the processing of XML data and can lead to unauthorized access to sensitive data.
4
Which version of Trend Micro Control Manager is affected by CVE-2017-11390?
CVE-2017-11390 specifically affects Trend Micro Control Manager version 6.0.
5
Can CVE-2017-11390 lead to data breaches?
Yes, if exploited, CVE-2017-11390 could lead to information disclosure, potentially resulting in data breaches.