Views:

Affected version(s)

ProductAffected versionPlatformLanguage(s)
Email Encryption GatewayVersion 5.5 build 1073 or earlierVirtual ApplianceEnglish

Solution

Trend Micro categorized this update with the impact level and recommends users update their installation to the newest version:

ProductUpdated versionPlatformImpact Level
Email Encryption GatewayVersion 5.5 build 1107Virtual ApplianceHigh

Vulnerability Details

This update resolves a vulnerability in Trend Micro Email Encryption Gateway 5.5 in which authentication could potentially be bypassed with an SQL injection under certain circumstances. Customers are highly encouraged to update to the latest build as soon as possible.

Acknowledgment

Trend Micro would like to thank Anonymous working with Trend Micro’s Zero Day Initiative (ZDI) for responsibly disclosing this issue and working with Trend Micro to help protect our customers.

External Reference(s)

ZDI-16-248