← Back to browse · API

CVE-2022-40139

Severity
HIGH
CVSS
7.2
EPSS
0.02837
Risk score
54.79
CISA KEV
Yes
PoC
No
Published
2022-09-15
Modified
2022-09-15
First seen
2026-08-07
Aliases
EUVD-2022-43457, GHSA-6H63-J29F-RV95
Products
Trend Micro:Apex One and Apex One as a Service, Trend Micro:Trend Micro Apex One 2019 (on-prem) and SaaS
Sources
euvd EUVD-2022-43457
cisa.gov CVE-2022-40139

Description

Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.

References