Vulnerabilities > Proofpoint
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-10-13 | CVE-2021-40843 | Deserialization of Untrusted Data vulnerability in Proofpoint Insider Threat Management Server Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. | 6.9 |
2021-10-13 | CVE-2021-34814 | Unspecified vulnerability in Proofpoint Spam Engine Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass. | 5.0 |
2021-10-13 | CVE-2021-39304 | Unspecified vulnerability in Proofpoint Enterprise Protection 8.12.02107140000 Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass. | 5.0 |
2021-05-07 | CVE-2020-14009 | Improper Validation of Integrity Check Value vulnerability in Proofpoint Enterprise Protection 8.14.2 Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. | 6.8 |
2021-04-06 | CVE-2021-27900 | Missing Authorization vulnerability in Proofpoint Insider Threat Management The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. | 5.5 |
2021-04-06 | CVE-2021-27899 | Improper Certificate Validation vulnerability in Proofpoint Insider Threat Management The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-middle attack. | 5.8 |
2021-04-06 | CVE-2021-22158 | XXE vulnerability in Proofpoint Insider Threat Management The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. | 6.5 |
2021-04-06 | CVE-2021-22157 | Cross-site Scripting vulnerability in Proofpoint Insider Threat Management Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS. | 4.3 |
2021-01-26 | CVE-2021-22159 | Improper Privilege Management vulnerability in Proofpoint Insider Threat Management Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25 as well as versions 7.3 and earlier is missing authentication for a critical function, which allows a local authenticated Windows user to run arbitrary commands with the privileges of the Windows SYSTEM user. | 7.2 |
2021-01-06 | CVE-2020-8884 | Deserialization of Untrusted Data vulnerability in Proofpoint Insider Threat Management rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes. | 9.0 |