CVE-2017-11398: Trend Micro Smart Protection Server
High severity, CVSS 8.8. EPSS: 8.2% chance of exploitation in the next 30 days.
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.
Affected products
- Trend Micro Smart Protection Server: up to and including 3.2
Published 2018-01-19. Last modified 2026-06-17.