SQL Injection Vulnerabilities in Trend Micro Apex Central
CVE-2023-32529
8.8HIGH
Summary
The on-premise version of Trend Micro Apex Central has multiple vulnerabilities that enable authenticated users to execute SQL injection attacks. This can potentially lead to remote code execution, putting sensitive data and system integrity at risk. To exploit these vulnerabilities, an attacker must first gain authentication on the target system, creating a significant threat for environments deploying affected versions of this security solution. Organizations should assess their systems for exposure to ensure they are safeguarded against these risks.
Affected Version(s)
Trend Micro Apex Central 2019 (8.0) < 8.0.0.6394
References
EPSS Score
1% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved