Vulnerabilities > CVE-2018-6225 - XXE vulnerability in Trendmicro Email Encryption Gateway 5.5

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
trendmicro
CWE-611
exploit available

Summary

An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to expose a normally protected configuration script.

Vulnerable Configurations

Part Description Count
Application
Trendmicro
1

Exploit-Db

descriptionTrend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities. CVE-2018-6219,CVE-2018-6220,CVE-2018-6221,CVE-2018-6222,CVE-2018-6223,CV...
fileexploits/jsp/webapps/44166.txt
idEDB-ID:44166
last seen2018-02-22
modified2018-02-22
platformjsp
port
published2018-02-22
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44166/
titleTrend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146508/CORE-2017-0006.txt
idPACKETSTORM:146508
last seen2018-02-24
published2018-02-21
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/146508/Trend-Micro-Email-Encryption-Gateway-XSS-Code-Execution.html
titleTrend Micro Email Encryption Gateway XSS / Code Execution