Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
proofpoint insider threat management vulnerabilities and exploits
(subscribe to this query)
801
VMScore
CVE-2020-8884
rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) prior to 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.
Proofpoint Insider Threat Management
578
VMScore
CVE-2021-22158
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. The vulnerability requires admin user privileges and knowledge of the XML file's encryption key to successfully exploit. All v...
Proofpoint Insider Threat Management
NA
CVE-2023-35998
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an malicious user to first obtain a valid agent authentication toke...
Proofpoint Insider Threat Management Server
NA
CVE-2023-36002
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions prior to 7.14.3 are affected.
Proofpoint Insider Threat Management Server
668
VMScore
CVE-2020-10655
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) prior to 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote malicious user to execute arbitrary code with local administ...
Proofpoint Insider Threat Management Server
578
VMScore
CVE-2020-10657
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) prior to 7.9.1 contains a vulnerability in the ITM web console's ImportAlertRules feature. The vulnerability allows a remote attacker (with admin or config-admin privileges in the console) to execute...
Proofpoint Insider Threat Management Server
668
VMScore
CVE-2020-10658
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) prior to 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote malicious user to execute arbitrary code with local administrator ...
Proofpoint Insider Threat Management Server
614
VMScore
CVE-2021-40843
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the local database could cause arbitrary code to execute with SYSTEM privileges on the underlying server when a Web Console user trigg...
Proofpoint Insider Threat Management Server
668
VMScore
CVE-2020-10656
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) prior to 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote malicious user to execute arbitrary code with lo...
Proofpoint Insider Threat Management Server
NA
CVE-2023-36000
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an malicious user to first obtain a valid agent a...
Proofpoint Insider Threat Management Server
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »