« Volver al listado

CVE-2019-9489

Estado: ModificadaAlta (7.5)—

A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-9489",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@trendmicro.com",
      "affectedData": [
        {
          "vendor": "Trend Micro",
          "product": "Apex One, OfficeScan, Worry-Free Business Security",
          "versions": [
            {
              "status": "affected",
              "version": "Apex One"
            },
            {
              "status": "affected",
              "version": "OfficeScan XG"
            },
            {
              "status": "affected",
              "version": "OfficeScan 11.0"
            },
            {
              "status": "affected",
              "version": "Worry-Free Business Security 10"
            },
            {
              "status": "affected",
              "version": "Worry-Free Business Security 9.5"
            },
            {
              "status": "affected",
              "version": "Worry-Free Business Security 9.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-04-05T23:29:00.220",
  "references": [
    {
      "url": "https://success.trendmicro.com/jp/solution/1122253",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://success.trendmicro.com/solution/1122250",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://success.trendmicro.com/jp/solution/1122253",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://success.trendmicro.com/solution/1122250",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de salto de directorio en Trend Micro Apex One, OfficeScan (en versiones XG y 11.0) y Worry-Free Business Security (en versiones 10.0, 9.5 y 9.0) podría permitir que un atacante modifique archivos arbitrarios en la consola de gestión del producto afectado."
    }
  ],
  "lastModified": "2026-06-17T02:43:48.380",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:trendmicro:apex_one:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7EF3C5E-0D35-4588-A21D-0D1D0352B85E",
              "versionEndIncluding": "b1066"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:apex_one_as_a_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65520AF0-2CDB-41BC-A9DE-7EA03D860AAA",
              "versionEndExcluding": "2019-03-27"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:business_security:9.0:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCA71A35-CEF5-4B5A-B123-ACDE49EE2B31"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:officescan:11.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFFB25C1-828D-49C4-825D-43AF1A2B7A55"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:officescan:xg:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "602A0266-B586-447A-A500-1145B77053E8"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64600B42-4884-41F2-A683-AE1EDB79372E"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:worry-free_business_security:9.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E482D0E-3CC6-4D32-AC2E-6A506066ECAB"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:worry-free_business_security:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42643A4A-D30D-40C4-9325-1F3B67A163CB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@trendmicro.com"
}