CVE Vulnerabilities

CVE-2025-49215

Use of Inherently Dangerous Function

Published: Jun 17, 2025 | Modified: Jun 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

Weakness

The product calls a function that can never be guaranteed to work safely.

Potential Mitigations

References