First published: Wed Aug 10 2016(Updated: )
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Mobile Control | <=3.5.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6597 has a medium severity level, indicating potential impact but requiring specific conditions to exploit.
To mitigate CVE-2016-6597, upgrade to Sophos Mobile Control EAS Proxy version 6.2.0 or later.
CVE-2016-6597 specifically affects Sophos Mobile Control EAS Proxy versions prior to 6.2.0 when Lotus Traveler is enabled.
The impact of CVE-2016-6597 allows remote attackers to access arbitrary web resources from the backend mail system.
Yes, CVE-2016-6597 is classified as an Open Reverse Proxy vulnerability.