PT-2022-14056 · Forcepoint · Forcepoint Web Security Content Gateway+4

Kaushik Joshi

+1

·

Published

2022-09-12

·

Updated

2022-09-15

·

CVE-2022-1700

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Forcepoint Data Loss Prevention (DLP) versions prior to 8.8.2 Forcepoint One Endpoint (F1E) with Policy Engine versions prior to 8.8.2 Forcepoint Web Security Content Gateway versions prior to 8.5.5 Forcepoint Email Security with DLP enabled versions prior to 8.5.5 Forcepoint Cloud Security Gateway prior to June 20, 2022
Description The issue is related to an Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine. The XML parser was found to be improperly configured to support external entities and external DTD (Document Type Definitions), which can lead to an XXE attack.
Recommendations For Forcepoint Data Loss Prevention (DLP) versions prior to 8.8.2, update to version 8.8.2 or later. For Forcepoint One Endpoint (F1E) with Policy Engine versions prior to 8.8.2, update the Policy Engine to version 8.8.2 or later. For Forcepoint Web Security Content Gateway versions prior to 8.5.5, update to version 8.5.5 or later. For Forcepoint Email Security with DLP enabled versions prior to 8.5.5, update to version 8.5.5 or later. For Forcepoint Cloud Security Gateway prior to June 20, 2022, ensure that updates after June 20, 2022, are applied.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-1700

Affected Products

Forcepoint Cloud Security Gateway
Forcepoint Data Loss Prevention
Forcepoint Email Security
Forcepoint One Endpoint
Forcepoint Web Security Content Gateway