Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote malicious users to bypass authentication via a brute force attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
trend micro scanmail 11.0 |
||
trend micro scanmail 10.2 |