ZeroHour

CVE-2017-11398

PoC
CVSS 3.0
8.8 high
EPSS
8%p95
Published
()
Modified
Description

A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.

Vendors
trendmicro
Products
smart protection server
Weakness
CWE-285, CWE-534
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.