CVE-2023-35998

A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:proofpoint:insider_threat_management_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-27 15:15

Updated : 2023-07-06 15:38


NVD link : CVE-2023-35998

Mitre link : CVE-2023-35998

CVE.ORG link : CVE-2023-35998


JSON object : View

Products Affected

proofpoint

  • insider_threat_management_server
CWE
CWE-862

Missing Authorization