Unrated severityNVD Advisory· Published Mar 8, 2023· Updated Feb 28, 2025
Proofpoint Enterprise Protection webservices unauthenticated RCE
CVE-2023-0090
Description
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.
Affected products
1- Range: 8.*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.