First published: Mon Oct 28 2019(Updated: )
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Apex One | ||
Trend Micro OfficeScan Corporate Edition | =11.0-sp1 | |
Trend Micro OfficeScan Corporate Edition | =xg | |
Trend Micro OfficeScan Corporate Edition | =xg-sp1 | |
Trend Micro Apex One and Worry-Free Business Security | =9.5 | |
Trend Micro Apex One and Worry-Free Business Security | =10.0 | |
Trend Micro Apex One and Worry-Free Business Security | =10.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18189 is a directory traversal vulnerability in Trend Micro Apex One, OfficeScan, and Worry-Free Business Security.
The severity of CVE-2019-18189 is rated as critical with a CVSS score of 9.8.
CVE-2019-18189 allows an attacker to bypass authentication and log on to the affected product's management console as a root user.
CVE-2019-18189 affects Trend Micro Apex One (all versions), Trend Micro OfficeScan 11.0 (SP1), Trend Micro OfficeScan XG (all versions), Trend Micro Worry-Free Business Security 9.5 and 10.0 (all versions).
Apply the necessary patches or updates provided by Trend Micro to address the CVE-2019-18189 vulnerability.