CVE Vulnerabilities

CVE-2020-28577

Published: Dec 01, 2020 | Modified: Jul 21, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.

Affected Software

Name Vendor Start Version End Version
Apex_one Trendmicro 2019 (including) 2019 (including)
Officescan Trendmicro xg-sp1 (including) xg-sp1 (including)

References