PT-2022-14056 · Forcepoint · Forcepoint Web Security Content Gateway+4
Kaushik Joshi
+1
·
Published
2022-09-12
·
Updated
2022-09-15
·
CVE-2022-1700
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Forcepoint Data Loss Prevention (DLP) versions prior to 8.8.2
Forcepoint One Endpoint (F1E) with Policy Engine versions prior to 8.8.2
Forcepoint Web Security Content Gateway versions prior to 8.5.5
Forcepoint Email Security with DLP enabled versions prior to 8.5.5
Forcepoint Cloud Security Gateway prior to June 20, 2022
Description
The issue is related to an Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine. The XML parser was found to be improperly configured to support external entities and external DTD (Document Type Definitions), which can lead to an XXE attack.
Recommendations
For Forcepoint Data Loss Prevention (DLP) versions prior to 8.8.2, update to version 8.8.2 or later.
For Forcepoint One Endpoint (F1E) with Policy Engine versions prior to 8.8.2, update the Policy Engine to version 8.8.2 or later.
For Forcepoint Web Security Content Gateway versions prior to 8.5.5, update to version 8.5.5 or later.
For Forcepoint Email Security with DLP enabled versions prior to 8.5.5, update to version 8.5.5 or later.
For Forcepoint Cloud Security Gateway prior to June 20, 2022, ensure that updates after June 20, 2022, are applied.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forcepoint Cloud Security Gateway
Forcepoint Data Loss Prevention
Forcepoint Email Security
Forcepoint One Endpoint
Forcepoint Web Security Content Gateway