Vulnerabilities > CVE-2022-3980 - XXE vulnerability in Sophos Mobile 5.0.0/9.7.3/9.7.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |