Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
proofpoint insider threat management vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-4801
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All ...
Proofpoint Insider Threat Management
NA
CVE-2023-4802
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's brow...
Proofpoint Insider Threat Management
NA
CVE-2023-4803
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. Al...
Proofpoint Insider Threat Management
NA
CVE-2023-4828
An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an malicious user to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL. T...
Proofpoint Insider Threat Management
NA
CVE-2023-2818
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions before 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected.
Proofpoint Insider Threat Management
NA
CVE-2023-35998
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an malicious user to first obtain a valid agent authentication toke...
Proofpoint Insider Threat Management Server
NA
CVE-2023-36000
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an malicious user to first obtain a valid agent a...
Proofpoint Insider Threat Management Server
NA
CVE-2023-36002
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions prior to 7.14.3 are affected.
Proofpoint Insider Threat Management Server
7.2
CVSSv2
CVE-2022-25294
Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges. All versions before 7.12.1 are affected. Agents for MacOS and Linux and Cloud are u...
Proofpoint Insider Threat Management
6.9
CVSSv2
CVE-2021-40843
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the local database could cause arbitrary code to execute with SYSTEM privileges on the underlying server when a Web Console user trigg...
Proofpoint Insider Threat Management Server
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »