Vulnerability Details CVE-2021-22158
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. The vulnerability requires admin user privileges and knowledge of the XML file's encryption key to successfully exploit. All versions before 7.11 are affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.4%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2021-22158
-
cpe:2.3:a:proofpoint:insider_threat_management:7.10.0
-
cpe:2.3:a:proofpoint:insider_threat_management:7.10.2
-
cpe:2.3:a:proofpoint:insider_threat_management:7.11.0.0
-
cpe:2.3:a:proofpoint:insider_threat_management:7.11.0.25
-
cpe:2.3:a:proofpoint:insider_threat_management:7.9.0