CVE-2025-30680

HIGH

Trend Micro Apex Central (SaaS) < 2025-03-01 - Server-Side Request Forgery via Parameter Manipulation

Title source: llm
STIX 2.1

Description

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. Please note: this vulnerability only affects the SaaS instance of Apex Central - customers that automatically apply Trend Micro's monthly maintenance releases to the SaaS instance do not have to take any further action.

References (2)

Core 2

Scores

CVSS v3 7.1
EPSS 0.0027
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
trendmicro/apex_central < 2025-03-01
Published Jun 17, 2025
Tracked Since Feb 18, 2026