Back to Database
Status published
Medium
CVE-2023-36002
ITM Server Missing Authorization for URL validation
Vulnerability Description
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-36002
Credits & Attribution
No credits recorded in the NVD database.
More from Proofpoint
View All →CVE-2025-8558
Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication...
Low
2.3
CVE-2025-0431
Enterprise Protection Backslash URL Rewrite Bypass
Medium
5.8
CVE-2024-3676
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an...
High
7.5
CVE-2024-10635
Enterprise Protection S/MIME Opaque Signature Attachment Scanning Bypass
Medium
6.1
CVE-2024-0862
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a...
Medium
5
Affected Vendor
Proofpoint
View all reports →Affected Software
Insider Threat Management
Vulnerable Versions:
0
Timeline
Official Publish:
June 27th, 2023
Last Modified:
November 6th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N