Vulnerabilites related to Trend Micro - Apex One, OfficeScan, Worry-Free Business Security
CVE-2019-9489 (GCVE-0-2019-9489)
Vulnerability from cvelistv5
Published
2019-04-05 22:46
Modified
2024-08-04 21:54
Severity ?
CWE
  • Directory Traversal
Summary
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
References
Impacted products
Vendor Product Version
Trend Micro Apex One, OfficeScan, Worry-Free Business Security Version: Apex One
Version: OfficeScan XG
Version: OfficeScan 11.0
Version: Worry-Free Business Security 10
Version: Worry-Free Business Security 9.5
Version: Worry-Free Business Security 9.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T21:54:44.231Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://success.trendmicro.com/solution/1122250"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://success.trendmicro.com/jp/solution/1122253"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Apex One, OfficeScan, Worry-Free Business Security",
          "vendor": "Trend Micro",
          "versions": [
            {
              "status": "affected",
              "version": "Apex One"
            },
            {
              "status": "affected",
              "version": "OfficeScan XG"
            },
            {
              "status": "affected",
              "version": "OfficeScan 11.0"
            },
            {
              "status": "affected",
              "version": "Worry-Free Business Security 10"
            },
            {
              "status": "affected",
              "version": "Worry-Free Business Security 9.5"
            },
            {
              "status": "affected",
              "version": "Worry-Free Business Security 9.0"
            }
          ]
        }
      ],
      "datePublic": "2019-04-03T00:00:00",
      "descriptions": [
        {
          "lang": "en",
          "value": "A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product\u0027s management console."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Directory Traversal",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2019-04-10T14:23:33",
        "orgId": "7f7bd7df-cffe-4fdb-ab6d-859363b89272",
        "shortName": "trendmicro"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://success.trendmicro.com/solution/1122250"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://success.trendmicro.com/jp/solution/1122253"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "security@trendmicro.com",
          "ID": "CVE-2019-9489",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Apex One, OfficeScan, Worry-Free Business Security",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "Apex One"
                          },
                          {
                            "version_value": "OfficeScan XG"
                          },
                          {
                            "version_value": "OfficeScan 11.0"
                          },
                          {
                            "version_value": "Worry-Free Business Security 10"
                          },
                          {
                            "version_value": "Worry-Free Business Security 9.5"
                          },
                          {
                            "version_value": "Worry-Free Business Security 9.0"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Trend Micro"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product\u0027s management console."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Directory Traversal"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://success.trendmicro.com/solution/1122250",
              "refsource": "CONFIRM",
              "url": "https://success.trendmicro.com/solution/1122250"
            },
            {
              "name": "https://success.trendmicro.com/jp/solution/1122253",
              "refsource": "CONFIRM",
              "url": "https://success.trendmicro.com/jp/solution/1122253"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7f7bd7df-cffe-4fdb-ab6d-859363b89272",
    "assignerShortName": "trendmicro",
    "cveId": "CVE-2019-9489",
    "datePublished": "2019-04-05T22:46:14",
    "dateReserved": "2019-03-01T00:00:00",
    "dateUpdated": "2024-08-04T21:54:44.231Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}