A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges.
Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://success.trendmicro.com/en-US/solution/KA-0019386 |
![]() ![]() |
History
Mon, 07 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 03 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Apr 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability. | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: trendmicro
Published: 2025-04-02T16:39:12.847Z
Updated: 2025-04-07T13:42:31.952Z
Reserved: 2025-03-27T17:59:57.531Z
Link: CVE-2025-31283

Updated: 2025-04-02T17:33:08.253Z

Status : Awaiting Analysis
Published: 2025-04-02T17:15:47.903
Modified: 2025-04-07T14:18:49.830
Link: CVE-2025-31283

No data.