Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.
References
Configurations
Information
Published : 2016-08-10 07:59
Updated : 2018-10-09 13:00
NVD link : CVE-2016-6597
Mitre link : CVE-2016-6597
JSON object : View
CWE
CWE-254
7PK - Security Features
Products Affected
sophos
- mobile_control_eas_proxy