Show plain JSON{"id": "CVE-2017-11386", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2017-08-02T21:29:00.307", "references": [{"url": "http://www.securityfocus.com/bid/100078", "source": "security@trendmicro.com"}, {"url": "http://www.securitytracker.com/id/1039049", "source": "security@trendmicro.com"}, {"url": "http://www.zerodayinitiative.com/advisories/ZDI-17-496", "tags": ["Third Party Advisory", "VDB Entry"], "source": "security@trendmicro.com"}, {"url": "https://success.trendmicro.com/solution/1117722", "tags": ["Patch", "Vendor Advisory"], "source": "security@trendmicro.com"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-89"}]}], "descriptions": [{"lang": "en", "value": "SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549."}, {"lang": "es", "value": "Una vulnerabilidad de inyecci\u00f3n SQL en Trend Micro Control Manager 6.0 permite la ejecuci\u00f3n de c\u00f3digo remoto cuando se ejecuta opcode 0x4707 por no haber una validaci\u00f3n de los datos de entrada del usuario correcta en cmdHandlerNewReportScheduler.dll. Anteriormente esta vulnerabilidad ten\u00eda el c\u00f3digo ZDI-CAN-4549."}], "lastModified": "2017-08-06T01:29:00.687", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:trendmicro:control_manager:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F7E3779-69E4-46AB-94E3-4A81E35A5194"}], "operator": "OR"}]}], "sourceIdentifier": "security@trendmicro.com"}