Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of 8.21, 8.20 and 8.18 prior to 8.21.0 patch 5115, 8.20.6 patch 5114 and 8.18.6 patch 5113 respectively.
History

Wed, 19 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of 8.21, 8.20 and 8.18 prior to 8.21.0 patch 5115, 8.20.6 patch 5114 and 8.18.6 patch 5113 respectively.
Title Enterprise Protection Backslash URL Rewrite Bypass
Weaknesses CWE-790
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Proofpoint

Published:

Updated: 2025-03-19T17:38:26.546Z

Reserved: 2025-01-13T19:25:35.786Z

Link: CVE-2025-0431

cve-icon Vulnrichment

Updated: 2025-03-19T17:38:05.093Z

cve-icon NVD

Status : Received

Published: 2025-03-19T17:15:41.217

Modified: 2025-03-19T17:15:41.217

Link: CVE-2025-0431

cve-icon Redhat

No data.