First published: Fri Jan 19 2018(Updated: )
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Smart Protection Server | <=3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11398 is a high severity vulnerability that allows session hijacking through log disclosure.
To fix CVE-2017-11398, upgrade to Trend Micro Smart Protection Server version 3.3 or later.
CVE-2017-11398 affects users of Trend Micro Smart Protection Server versions 3.2 and below.
CVE-2017-11398 allows unauthenticated attackers to hijack active user sessions and perform authenticated actions.
There are no specific workarounds documented for CVE-2017-11398; upgrading is recommended.