A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/102275 | Third Party Advisory VDB Entry |
https://success.trendmicro.com/solution/1118992 | Vendor Advisory |
https://www.coresecurity.com/advisories/trend-micro-smart-protection-server-multiple-vulnerabilities | Exploit Third Party Advisory |
https://www.exploit-db.com/exploits/43388/ | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: trendmicro
Published: 2018-01-19T19:00:00
Updated: 2018-01-20T10:57:01
Reserved: 2017-07-17T00:00:00
Link: CVE-2017-11398
JSON object: View
NVD Information
Status : Modified
Published: 2018-01-19T19:29:00.280
Modified: 2019-10-09T23:22:04.543
Link: CVE-2017-11398
JSON object: View
Redhat Information
No data.