NA

CVE-2023-35998

Published: 27/06/2023 Updated: 06/07/2023
CVSS v3 Base Score: 4.6 | Impact Score: 2.5 | Exploitability Score: 2.1
VMScore: 0

Vulnerability Summary

A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an malicious user to first obtain a valid agent authentication token. All versions prior to 7.14.3 are affected.

Vulnerable Product Search on Vulmon Subscribe to Product

proofpoint insider threat management server