Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w3v-7x22-4g8v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations.

Please note: an attacker must first obtain the ability to logon to the product’s management console in order to exploit this vulnerability.

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations.

Please note: an attacker must first obtain the ability to logon to the product’s management console in order to exploit this vulnerability.

EPSS

Процентиль: 68%
0.00582
Низкий

8.8 High

CVSS3

Дефекты

CWE-20
CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость антивирусных программных средств Trend Micro Worry-Free Business Security и Apex One, связанная с отсутствием ограничений на загрузку файлов, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 68%
0.00582
Низкий

8.8 High

CVSS3

Дефекты

CWE-20
CWE-434