CVE-2023-35998
Summary
| CVE | CVE-2023-35998 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-27 15:15:00 UTC |
| Updated | 2023-07-06 15:38:00 UTC |
| Description | A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Proofpoint | Insider Threat Management Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ITM Windows Agent Insecure Filesystem Permissions | Proofpoint US | MISC | www.proofpoint.com | |
| ITM Server Multiple Vulnerabilities | Proofpoint US | MISC | www.proofpoint.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.