Trend Micro Control Manager vulnerabilities

11 known vulnerabilities affecting trend_micro/trend_micro_control_manager.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2018-10510CRITICALCVSS 9.8v6.0 and 7.02018-08-15
CVE-2018-10510 [CRITICAL] CWE-22 CVE-2018-10510: A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6 A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.
cvelistv5nvd
CVE-2018-10511CRITICALCVSS 10.0v6.0 and 7.02018-08-15
CVE-2018-10511 [CRITICAL] CWE-918 CVE-2018-10511: A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to con A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.
cvelistv5nvd
CVE-2018-10512HIGHCVSS 7.5v6.0 and 7.02018-08-15
CVE-2018-10512 [HIGH] CVE-2018-10512: A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to man A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, which may lead to a denial of server (DoS).
cvelistv5nvd
CVE-2018-3601CRITICALCVSS 9.8v6.02018-02-09
CVE-2018-3601 [CRITICAL] CWE-287 CVE-2018-3601: A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could a A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerable installations.
cvelistv5nvd
CVE-2018-3607HIGHCVSS 8.8v6.02018-02-09
CVE-2018-3607 [HIGH] CWE-89 CVE-2018-3607: XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
cvelistv5nvd
CVE-2018-3604HIGHCVSS 8.8v6.02018-02-09
CVE-2018-3604 [HIGH] CWE-89 CVE-2018-3604: GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manag GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
cvelistv5nvd
CVE-2018-3602HIGHCVSS 8.8v6.02018-02-09
CVE-2018-3602 [HIGH] CWE-89 CVE-2018-3602: An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Contr An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
cvelistv5nvd
CVE-2018-3603HIGHCVSS 8.8v6.02018-02-09
CVE-2018-3603 [HIGH] CWE-89 CVE-2018-3603: A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
cvelistv5nvd
CVE-2018-3606HIGHCVSS 8.8v6.02018-02-09
CVE-2018-3606 [HIGH] CWE-89 CVE-2018-3606: XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution ( XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
cvelistv5nvd
CVE-2018-3605HIGHCVSS 8.8v6.02018-02-09
CVE-2018-3605 [HIGH] CWE-89 CVE-2018-3605: TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabiliti TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
cvelistv5nvd
CVE-2018-3600MEDIUMCVSS 6.5v6.02018-02-09
CVE-2018-3600 [MEDIUM] CWE-611 CVE-2018-3600: A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manag A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive information on vulnerable installations.
cvelistv5nvd