CVE-2022-41746Forced Browsing in Micro Apex ONE

CWE-425Forced Browsing3 documents3 sources
Severity
9.1CRITICALNVD
EPSS
0.6%
top 30.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateOct 11

Description

A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex One web console in order to exploit this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages2 packages

CVEListV5trend_micro/trend_micro_apex_one2019 (on-prem) and SaaS

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7r5j-q244-pc8m: A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escal2022-10-11
CVEList
CVE-2022-41746: A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escal2022-10-10
CVE-2022-41746 — Forced Browsing in Trend | cvebase