Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the local database could cause arbitrary code to execute with SYSTEM privileges on the underlying server when a Web Console user triggers retrieval of that data. When chained with a SQL injection vulnerability, the vulnerability could be exploited remotely if Web Console users click a series of maliciously crafted URLs. All versions prior to 7.11.2 are affected.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Proofpoint Insider Threat Management Server 代码问题漏洞
Vulnerability Description
Proofpoint Insider Threat Management Server是美国Proofpoint公司的一款应用于防止企业内部人员恶意操作的服务端应用。 Proofpoint Insider Threat Management Server 存在安全漏洞,该漏洞源于Proofpoint Insider Threat Management Server在Web控制台中包含一个不安全的反序列化漏洞。攻击者可利用该漏洞导致使用SYSTEM特权在底层服务器上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A