{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-03T04:09:09.696","vulnerabilities":[{"cve":{"id":"CVE-2019-9489","sourceIdentifier":"security@trendmicro.com","published":"2019-04-05T23:29:00.220","lastModified":"2024-11-21T04:51:43.077","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console."},{"lang":"es","value":"Una vulnerabilidad de salto de directorio en Trend Micro Apex One, OfficeScan (en versiones XG y 11.0) y Worry-Free Business Security (en versiones 10.0, 9.5 y 9.0) podría permitir que un atacante modifique archivos arbitrarios en la consola de gestión del producto afectado."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:apex_one:*:*:*:*:*:*:*:*","versionEndIncluding":"b1066","matchCriteriaId":"E7EF3C5E-0D35-4588-A21D-0D1D0352B85E"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:apex_one_as_a_service:*:*:*:*:*:*:*:*","versionEndExcluding":"2019-03-27","matchCriteriaId":"65520AF0-2CDB-41BC-A9DE-7EA03D860AAA"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:business_security:9.0:sp3:*:*:*:*:*:*","matchCriteriaId":"DCA71A35-CEF5-4B5A-B123-ACDE49EE2B31"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:officescan:11.0:sp1:*:*:*:*:*:*","matchCriteriaId":"CFFB25C1-828D-49C4-825D-43AF1A2B7A55"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:officescan:xg:*:*:*:*:*:*:*","matchCriteriaId":"602A0266-B586-447A-A500-1145B77053E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*","matchCriteriaId":"64600B42-4884-41F2-A683-AE1EDB79372E"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:worry-free_business_security:9.5:*:*:*:*:*:*:*","matchCriteriaId":"6E482D0E-3CC6-4D32-AC2E-6A506066ECAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:worry-free_business_security:10.0:*:*:*:*:*:*:*","matchCriteriaId":"42643A4A-D30D-40C4-9325-1F3B67A163CB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://success.trendmicro.com/jp/solution/1122253","source":"security@trendmicro.com","tags":["Patch","Vendor Advisory"]},{"url":"https://success.trendmicro.com/solution/1122250","source":"security@trendmicro.com","tags":["Patch","Vendor Advisory"]},{"url":"https://success.trendmicro.com/jp/solution/1122253","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://success.trendmicro.com/solution/1122250","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}