SQL Injection Vulnerabilities in Trend Micro Apex Central
CVE-2023-32529

8.8HIGH

Key Information:

Vendor
CVE Published:
26 June 2023

Summary

The on-premise version of Trend Micro Apex Central has multiple vulnerabilities that enable authenticated users to execute SQL injection attacks. This can potentially lead to remote code execution, putting sensitive data and system integrity at risk. To exploit these vulnerabilities, an attacker must first gain authentication on the target system, creating a significant threat for environments deploying affected versions of this security solution. Organizations should assess their systems for exposure to ensure they are safeguarded against these risks.

Affected Version(s)

Trend Micro Apex Central 2019 (8.0) < 8.0.0.6394

References

EPSS Score

1% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.