CVE-2018-6228: SQL Injection
Published Mar 15, 2018
·Updated
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
Affected Software
1 affected component
trendmicro Email Encryption Gateway=5.5
Remediation
Patch Available
Event History
Mar 15, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6228?
CVE-2018-6228 is considered a high severity SQL injection vulnerability that can lead to arbitrary code execution.
2
How do I fix CVE-2018-6228?
To fix CVE-2018-6228, update to the latest version of Trend Micro Email Encryption Gateway that addresses this vulnerability.
3
What systems are affected by CVE-2018-6228?
CVE-2018-6228 affects Trend Micro Email Encryption Gateway version 5.5.
4
What type of attack does CVE-2018-6228 allow?
CVE-2018-6228 allows an attacker to execute SQL commands that can compromise the target system.
5
Is CVE-2018-6228 easy to exploit?
CVE-2018-6228 can be easily exploited by attackers with knowledge of SQL injection techniques.