Forcepoint

Email Security

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 24.03.2025 16:06:39
  • Zuletzt bearbeitet 27.03.2025 16:44:44

Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messages module) allows Stored XSS. This issue affects Email Security through 8.5.5.

  • EPSS 0.24%
  • Veröffentlicht 04.09.2024 22:15:04
  • Zuletzt bearbeitet 12.09.2024 17:19:43

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.

  • EPSS 0.2%
  • Veröffentlicht 15.06.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 07:57:53

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.

  • EPSS 0.32%
  • Veröffentlicht 12.09.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:41:16

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP...

  • EPSS 0.25%
  • Veröffentlicht 08.04.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 05:36:01

Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

  • EPSS 0.36%
  • Veröffentlicht 05.11.2019 21:15:13
  • Zuletzt bearbeitet 21.11.2024 04:46:01

It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that you apply the relevant hotfix in order to remediate this issue.

  • EPSS 0.41%
  • Veröffentlicht 09.04.2019 21:29:03
  • Zuletzt bearbeitet 21.11.2024 04:46:01

A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not completed.

  • EPSS 4.98%
  • Veröffentlicht 09.04.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:55

A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process creating a denial-of-service. While no known Remote Code Execution (RCE) vulnerabilities exist, as with...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 28.03.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:55

A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.