#VU68067 Missing Authorization in Apex One - CVE-2022-41746
Published: October 8, 2022
Apex One
Trend Micro
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to missing authorization within the the Apex One web console. A remote authenticated user can bypass authorization and gain write access to server configuration via a specific URL. Successful exploitation of the vulnerability may allow an attacker to reconfigure the server and associated endpoint agents.