First published: Tue Jun 27 2023(Updated: )
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.
Credit: security@proofpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint | <7.14.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-36002.
The severity rating of CVE-2023-36002 is medium with a value of 4.3.
The affected software for CVE-2023-36002 is Proofpoint Insider Threat Management Server versions before 7.14.3.
An anonymous attacker on an adjacent network can exploit CVE-2023-36002 by smuggling content via DNS lookups.
To fix CVE-2023-36002, upgrade to Proofpoint Insider Threat Management Server version 7.14.3 or later.