peter bassill · operator
$ cve CVE-2017-11398 JSON

CVE-2017-11398 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 8.2% (pctl 95)

Patch early

A public exploit exists.

Description

A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS8.2% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-285
On CISA KEVno
Public exploityes
Published2018-01-19
Last modified2026-06-17

Affected (1)

VendorProduct
trendmicrosmart protection server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD