First published: Thu Mar 15 2018(Updated: )
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Email Encryption Gateway | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6228 is considered a high severity SQL injection vulnerability that can lead to arbitrary code execution.
To fix CVE-2018-6228, update to the latest version of Trend Micro Email Encryption Gateway that addresses this vulnerability.
CVE-2018-6228 affects Trend Micro Email Encryption Gateway version 5.5.
CVE-2018-6228 allows an attacker to execute SQL commands that can compromise the target system.
CVE-2018-6228 can be easily exploited by attackers with knowledge of SQL injection techniques.