Trendmicro Apex One vulnerabilities

161 known vulnerabilities affecting trendmicro/apex_one.

Total CVEs
161
CISA KEV
9
actively exploited
Public exploits
0
Exploited in wild
8
Severity breakdown
CRITICAL8HIGH107MEDIUM46

Vulnerabilities

Page 7 of 9
CVE-2021-25234MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25234 [MEDIUM] CVE-2021-25234: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG S An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific notification configuration file.
nvd
CVE-2021-25228MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25228 [MEDIUM] CVE-2021-25228: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG S An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history.
nvd
CVE-2021-25241MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25241 [MEDIUM] CWE-918 CVE-2021-25241: A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One an A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.
nvd
CVE-2021-25243MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25243 [MEDIUM] CVE-2021-25243: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG S An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.
nvd
CVE-2021-25229MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25229 [MEDIUM] CVE-2021-25229: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan X An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server.
nvd
CVE-2021-25230MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25230 [MEDIUM] CVE-2021-25230: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan X An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file.
nvd
CVE-2021-25248MEDIUMCVSS 5.5v20192021-02-04
CVE-2021-25248 [MEDIUM] CWE-125 CVE-2021-25248: An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an attacker must first obtain the ability to execute low-privileged code on the t
nvd
CVE-2021-25235MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25235 [MEDIUM] CVE-2021-25235: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan X An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file.
nvd
CVE-2021-25246MEDIUMCVSS 6.5v20192021-02-04
CVE-2021-25246 [MEDIUM] CVE-2021-25246: An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.
nvd
CVE-2021-25233MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25233 [MEDIUM] CVE-2021-25233: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG S An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file.
nvd
CVE-2021-25232MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25232 [MEDIUM] CVE-2021-25232: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan X An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database.
nvd
CVE-2021-25242MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25242 [MEDIUM] CVE-2021-25242: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG S An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information.
nvd
CVE-2021-25239MEDIUMCVSS 5.3v20192021-02-04
CVE-2021-25239 [MEDIUM] CVE-2021-25239: An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and W An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes.
nvd
CVE-2020-28583MEDIUMCVSS 5.3v20192020-12-01
CVE-2020-28583 [MEDIUM] CVE-2020-28583: An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeSc An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.
nvd
CVE-2020-28577MEDIUMCVSS 5.3v20192020-12-01
CVE-2020-28577 [MEDIUM] CVE-2020-28577: An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeSc An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.
nvd
CVE-2020-28576MEDIUMCVSS 5.3v20192020-12-01
CVE-2020-28576 [MEDIUM] CVE-2020-28576: An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeSc An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.
nvd
CVE-2020-28582MEDIUMCVSS 5.3v20192020-12-01
CVE-2020-28582 [MEDIUM] CVE-2020-28582: An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeSc An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.
nvd
CVE-2020-28573MEDIUMCVSS 5.3v20192020-12-01
CVE-2020-28573 [MEDIUM] CVE-2020-28573: An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeSc An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.
nvd
CVE-2020-28572HIGHCVSS 7.8v20192020-11-18
CVE-2020-28572 [HIGH] CVE-2020-28572: A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product instal A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege.
nvd
CVE-2020-24563HIGHCVSS 7.8v2019vsaas2020-09-29
CVE-2020-24563 [HIGH] CWE-287 CVE-2020-24563: A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit this vulnerability
nvd