A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key…
trendmicro·CWE-23·Published 2026-05-21
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Una vulnerabilidad de salto de directorio en el servidor Apex One (local) podría permitir a un atacante local preautenticado modificar una tabla clave en el servidor para inyectar código malicioso y desplegarlo en agentes de instalaciones afectadas. Esta vulnerabilidad solo es explotable en la versión local de Apex One y un atacante potencial debe tener acceso al servidor Apex One y haber obtenido ya credenciales administrativas para el servidor mediante algún otro método para explotar esta vulnerabilidad.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 6.7 | — | — | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L |
| 3.1 | Secondary | NVD | 6.7 | 0.8 | 5.3 | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L |