CVE-2019-18189: Path Traversal
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18189?
CVE-2019-18189 is a directory traversal vulnerability in Trend Micro Apex One, OfficeScan, and Worry-Free Business Security.
What is the severity of CVE-2019-18189?
The severity of CVE-2019-18189 is rated as critical with a CVSS score of 9.8.
How does CVE-2019-18189 affect the affected software?
CVE-2019-18189 allows an attacker to bypass authentication and log on to the affected product's management console as a root user.
Which software versions are affected by CVE-2019-18189?
CVE-2019-18189 affects Trend Micro Apex One (all versions), Trend Micro OfficeScan 11.0 (SP1), Trend Micro OfficeScan XG (all versions), Trend Micro Worry-Free Business Security 9.5 and 10.0 (all versions).
How can I fix CVE-2019-18189?
Apply the necessary patches or updates provided by Trend Micro to address the CVE-2019-18189 vulnerability.