CVE-2017-11398: High severity trendmicro Smart Protection Server vulnerability
Published Jan 19, 2018
·Updated
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.
Affected Software
1 affected component
trendmicro Smart Protection Server<=3.2
Event History
Jan 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11398?
CVE-2017-11398 is a high severity vulnerability that allows session hijacking through log disclosure.
2
How do I fix CVE-2017-11398?
To fix CVE-2017-11398, upgrade to Trend Micro Smart Protection Server version 3.3 or later.
3
Who is affected by CVE-2017-11398?
CVE-2017-11398 affects users of Trend Micro Smart Protection Server versions 3.2 and below.
4
What type of attacks are possible with CVE-2017-11398?
CVE-2017-11398 allows unauthenticated attackers to hijack active user sessions and perform authenticated actions.
5
Is there a workaround for CVE-2017-11398?
There are no specific workarounds documented for CVE-2017-11398; upgrading is recommended.