Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9557 | A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://success.trendmicro.com/en-US/solution/KA-0019386 |
|
Tue, 02 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trendmicro
Trendmicro trend Vision One |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:trendmicro:trend_vision_one:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Trendmicro
Trendmicro trend Vision One |
Mon, 07 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 03 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability. | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2025-04-07T13:42:52.372Z
Reserved: 2025-03-27T17:59:57.531Z
Link: CVE-2025-31285
Updated: 2025-04-02T17:32:10.291Z
Status : Analyzed
Published: 2025-04-02T17:15:48.943
Modified: 2025-09-02T18:33:05.810
Link: CVE-2025-31285
No data.
OpenCVE Enrichment
No data.
EUVD