CVE-2022-40144

critical

Description

A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product’s login authentication by falsifying request parameters on affected installations.

References

https://www.ipa.go.jp/security/ciadr/vul/20220913-jvn.html

https://success.trendmicro.com/solution/000291528

https://appweb.trendmicro.com/SupportNews/NewsDetail.aspx?id=4553

https://jvn.jp/en/jp/JVN36454862/index.html

Details

Source: MITRE

Published: 2022-09-19

Updated: 2022-09-21

Type: CWE-287

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL