First published: Fri Feb 09 2018(Updated: )
GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Control Manager | =6.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-3604.
The title of the vulnerability is Trend Micro Control Manager sp_DDI_GetInterestedIPByJobID2 SQL Injection Remote Code Execution Vulnerability.
The severity of CVE-2018-3604 is high with a CVSS score of 8.8.
Trend Micro Control Manager version 6.0 is affected by CVE-2018-3604.
To fix CVE-2018-3604, update Trend Micro Control Manager to the latest version.