ZDI-23-1001: Trend Micro Apex Central modTXSO Server-Side Request Forgery Information Disclosure Vulnerability
Published Jul 26, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Trend Micro Apex Central
Event History
Jul 26, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Jan 23, 2024
Advisory Published
via ZDI·08:39 PM
Frequently Asked Questions
1
What is the severity of ZDI-23-1001?
The severity of ZDI-23-1001 is categorized as high due to its potential for sensitive information disclosure.
2
How do I fix ZDI-23-1001?
To fix ZDI-23-1001, ensure that your Trend Micro Apex Central is updated to the latest version provided by the vendor.
3
Who is impacted by ZDI-23-1001?
Organizations using affected versions of Trend Micro Apex Central with authentication enabled are impacted by ZDI-23-1001.
4
What type of attack is ZDI-23-1001 associated with?
ZDI-23-1001 is associated with remote information disclosure attacks requiring authentication.
5
Is authentication necessary for exploiting ZDI-23-1001?
Yes, authentication is required for attackers to exploit the ZDI-23-1001 vulnerability.