CVE Vulnerabilities

CVE-2022-41746

Direct Request ('Forced Browsing')

Published: Oct 10, 2022 | Modified: Oct 11, 2022
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex One web console in order to exploit this vulnerability.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Apex_one Trendmicro - (including) - (including)
Apex_one Trendmicro 2019 (including) 2019 (including)

Potential Mitigations

References