Vulnerabilities > Proofpoint > Insider Threat Management > 7.11.0.25

DATE CVE VULNERABILITY TITLE RISK
2023-09-13 CVE-2023-4802 Cross-site Scripting vulnerability in Proofpoint Insider Threat Management
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser.
network
low complexity
proofpoint CWE-79
4.8
2023-09-13 CVE-2023-4803 Cross-site Scripting vulnerability in Proofpoint Insider Threat Management
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser.
network
low complexity
proofpoint CWE-79
4.8
2023-09-13 CVE-2023-4828 Improper Check for Unusual or Exceptional Conditions vulnerability in Proofpoint Insider Threat Management
An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL.
network
high complexity
proofpoint CWE-754
4.2
2023-06-27 CVE-2023-2818 Improper Preservation of Permissions vulnerability in Proofpoint Insider Threat Management
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring.
local
low complexity
proofpoint CWE-281
5.5
2022-03-10 CVE-2022-25294 Unspecified vulnerability in Proofpoint Insider Threat Management
Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges.
local
low complexity
proofpoint
7.2
2021-04-06 CVE-2021-27900 Missing Authorization vulnerability in Proofpoint Insider Threat Management
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console.
network
low complexity
proofpoint CWE-862
5.5
2021-04-06 CVE-2021-22158 XXE vulnerability in Proofpoint Insider Threat Management
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console.
network
low complexity
proofpoint CWE-611
6.5
2021-04-06 CVE-2021-22157 Cross-site Scripting vulnerability in Proofpoint Insider Threat Management
Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
network
proofpoint CWE-79
4.3