CVE-2019-9489

A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:trendmicro:apex_one:*:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:apex_one_as_a_service:*:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:business_security:9.0:sp3:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:11.0:sp1:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:xg:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:9.5:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

24 Sep 2021, 13:40

Type Values Removed Values Added
References (CONFIRM) https://success.trendmicro.com/jp/solution/1122253 - Patch, Vendor Advisory (CONFIRM) https://success.trendmicro.com/jp/solution/1122253 - Vendor Advisory, Patch
CPE cpe:2.3:a:trendmicro:business_security:9.5:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:business_security:10.0:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:9.5:*:*:*:*:*:*:*

Information

Published : 2019-04-05 23:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-9489

Mitre link : CVE-2019-9489

CVE.ORG link : CVE-2019-9489


JSON object : View

Products Affected

trendmicro

  • business_security
  • officescan
  • apex_one
  • worry-free_business_security
  • apex_one_as_a_service

microsoft

  • windows
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')