CVE-2017-14078: SQL Injection
Published Sep 22, 2017
·Updated
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
Affected Software
1 affected component
trendmicro Mobile Security=9.7
Remediation
Patch Available
Event History
Sep 22, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14078?
CVE-2017-14078 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2017-14078?
To fix CVE-2017-14078, upgrade Trend Micro Mobile Security (Enterprise) to version 9.7 Patch 3 or later.
3
What types of attacks can CVE-2017-14078 facilitate?
CVE-2017-14078 can facilitate SQL injection attacks allowing attackers to execute arbitrary code.
4
Which versions of Trend Micro Mobile Security are affected by CVE-2017-14078?
CVE-2017-14078 affects all versions of Trend Micro Mobile Security (Enterprise) prior to 9.7 Patch 3.
5
Can I exploit CVE-2017-14078 without authentication?
Yes, CVE-2017-14078 can be exploited by remote attackers without requiring authentication.