CVE-2018-6225: XEE
Published Mar 15, 2018
·Updated
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to expose a normally protected configuration script.
Affected Software
1 affected component
trendmicro Email Encryption Gateway=5.5
Event History
Mar 15, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6225?
CVE-2018-6225 is classified as a medium-severity vulnerability due to its potential to expose sensitive configuration scripts.
2
How do I fix CVE-2018-6225?
To fix CVE-2018-6225, update Trend Micro Email Encryption Gateway to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2018-6225?
CVE-2018-6225 affects users of Trend Micro Email Encryption Gateway version 5.5.
4
What type of vulnerability is CVE-2018-6225?
CVE-2018-6225 is an XML external entity injection (XXE) vulnerability.
5
Can CVE-2018-6225 be exploited remotely?
CVE-2018-6225 requires authentication, making it less likely to be exploited remotely without user access.