« Volver al listado

CVE-2022-46332

Estado: ModificadaCrítica (9.6)—

The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-46332",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-46332",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-23T16:11:29.396664Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@proofpoint.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@proofpoint.com",
      "affectedData": [
        {
          "vendor": "proofpoint",
          "product": "enterprise_protection",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "8.19.0 patch 4546",
                  "status": "unaffected"
                },
                {
                  "at": "8.18.6 patch 4545",
                  "status": "unaffected"
                },
                {
                  "at": "8.18.4 patch 4544",
                  "status": "unaffected"
                },
                {
                  "at": "8.13.22 patch 4543",
                  "status": "unaffected"
                }
              ],
              "version": "8.*",
              "versionType": "semver",
              "lessThanOrEqual": "8.19.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-12-06T20:15:10.610",
  "references": [
    {
      "url": "https://www.proofpoint.com/security/security-advisories/pfpt-sa-2022-0002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@proofpoint.com"
    },
    {
      "url": "https://www.proofpoint.com/security/security-advisories/pfpt-sa-2022-0002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@proofpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface.  This affects all versions 8.19.0 and below.\n\n"
    },
    {
      "lang": "es",
      "value": "La función Admin Smart Search en Proofpoint Enterprise Protection (PPS/PoD) contiene una vulnerabilidad de cross-site scripting almacenado que permite a un remitente de correo electrónico anónimo obtener privilegios de administrador dentro de la interfaz de usuario. Esto afecta a todas las versiones 8.19.0 y anteriores."
    }
  ],
  "lastModified": "2026-06-17T05:11:32.877",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8989910-63F8-4E56-AC31-F2FF3FAB1991",
              "versionEndIncluding": "8.19.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@proofpoint.com"
}