CVE-2021-25246: Trend Micro Apex One Improper Access Control Information Disclosure Vulnerability
An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex One. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web console. The issue results from improper access control. An attacker can leverage this vulnerability to disclose information from the application.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-25246?
CVE-2021-25246 is a vulnerability that allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex One.
How does CVE-2021-25246 affect Trend Micro Apex One?
CVE-2021-25246 affects Trend Micro Apex One by allowing remote attackers to disclose sensitive information.
Is authentication required to exploit CVE-2021-25246?
No, authentication is not required to exploit CVE-2021-25246.
What is the severity of CVE-2021-25246?
CVE-2021-25246 has a severity rating of medium (6.5).
How can I fix CVE-2021-25246?
To fix CVE-2021-25246, apply the necessary security patches provided by Trend Micro.