CVE-2017-14093: XSS
Published Dec 15, 2017
·Updated
The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.
Affected Software
1 affected component
trendmicro Scanmail Microsoft Exchange=12.0
Remediation
Patch Available
Event History
Dec 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-14093.
2
What software is affected by this vulnerability?
The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are affected by this vulnerability.
3
What is the severity level of CVE-2017-14093?
The severity level of CVE-2017-14093 is medium (6.1).
4
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-79.
5
How can I fix the cross site scripting (XSS) vulnerability in Trend Micro ScanMail for Exchange 12.0?
To fix the cross site scripting (XSS) vulnerability in Trend Micro ScanMail for Exchange 12.0, it is recommended to apply the security patches released by the vendor. Additionally, the use of a web application firewall (WAF) or security monitoring tools can help mitigate the risk of XSS attacks.