CVE-2023-36002
Summary
| CVE | CVE-2023-36002 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-27 15:15:00 UTC |
| Updated | 2023-07-06 16:02:00 UTC |
| Description | A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Proofpoint | Insider Threat Management Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ITM Windows Agent Insecure Filesystem Permissions | Proofpoint US | MISC | www.proofpoint.com | |
| ITM Server Multiple Vulnerabilities | Proofpoint US | MISC | www.proofpoint.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.