A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges.
Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://success.trendmicro.com/en-US/solution/KA-0019386 |
![]() ![]() |
History
Mon, 07 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 02 Apr 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability. | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2025-04-07T13:42:21.662Z
Reserved: 2025-03-27T17:59:57.531Z
Link: CVE-2025-31282

No data.

Status : Awaiting Analysis
Published: 2025-04-02T17:15:46.473
Modified: 2025-04-07T14:18:49.830
Link: CVE-2025-31282

No data.