A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.
https://www.ipa.go.jp/security/ciadr/vul/20220913-jvn.html
https://jvn.jp/en/jp/JVN36454862/index.html
https://www.tenable.com/blog/cve-2022-40139-vulnerability-in-trend-micro-apex-one-exploited-in-the-wild
https://success.trendmicro.com/solution/000291528
https://appweb.trendmicro.com/SupportNews/NewsDetail.aspx?id=4553
Source: Mitre, NVD
Published: 2022-09-19
Updated: 2023-11-07
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00137