CVE-2016-6597

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
10/08/2016
Last modified:
12/04/2025

Description

Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sophos:mobile_control_eas_proxy:*:*:*:*:*:*:*:* 3.5.0.3 (including)