Back to Database
Status published
Medium
CVE-2021-22157
Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1...
Vulnerability Description
Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-22157
Credits & Attribution
No credits recorded in the NVD database.
More from proofpoint
View All →CVE-2023-0090
Proofpoint Enterprise Protection webservices unauthenticated RCE
Critical
9.8
CVE-2023-0089
Proofpoint Enterprise Protection webutils authenticated RCE
High
8.8
CVE-2022-46333
Proofpoint Enterprise Protection perl eval() arbitrary command execution
High
7.2
CVE-2022-46332
Proofpoint Enterprise Protection (PPS/PoD) XSS in "Attachment Names"
Critical
9.6
CVE-2022-25294
Proofpoint Insider Threat Management Agent for Windows relies on an...
High
7.8
Affected Vendor
proofpoint
View all reports →Affected Software
insider threat management
Vulnerable Versions:
7.9.0, 7.10.0, 7.11.0
Timeline
Official Publish:
April 6th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.