VYPR

Apex One

by Trend Micro

CVEs (180)

  • CVE-2021-25240MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx information.

  • CVE-2021-25239MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes.

  • CVE-2021-25237MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem) could allow an unauthenticated user to obtain information about the managing port used by agents.

  • CVE-2021-25235MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file.

  • CVE-2021-25234MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific notification configuration file.

  • CVE-2021-25233MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file.

  • CVE-2021-25232MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database.

  • CVE-2021-25231MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific hotfix history file.

  • CVE-2021-25230MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file.

  • CVE-2021-25229MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server.

  • CVE-2021-25228MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history.

  • CVE-2020-28583MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.

  • CVE-2020-28582MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.

  • CVE-2020-28577MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.

  • CVE-2020-28576MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.

  • CVE-2020-28573MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.

  • CVE-2023-32553MedJun 26, 2023
    risk 0.34cvss 5.3epss 0.00

    An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552.

  • CVE-2019-19691MedDec 20, 2019
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must already have admin/root privileges on the product console to exploit this…

  • CVE-2024-36307MedJun 10, 2024
    risk 0.31cvss 4.7epss 0.01

    A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2020-25774MedSep 29, 2020
    risk 0.28cvss 4.3epss 0.02

    A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to exploit this…

Page 9 of 9