CVE-2019-18189 Vulnerability Details

  /     /     /  

CVE-2019-18189 Metadata Quick Info

CVE Published: 28/10/2019 | CVE Updated: 05/08/2024 | CVE Year: 2019
Source: trendmicro | Vendor: Trend Micro | Product: Trend Micro Apex One, Trend Micro OfficeScan (OSCE), Trend Micro Worry-Free Business Security (WFBS)
Status : PUBLISHED

CVE-2019-18189 Description

A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product\'s management console as a root user. The vulnerability does not require authentication.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Root Login Bypass with Directory Traversal
Source: Trend Micro

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).