Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-6398
Disclosure Date: July 15, 2024 (last updated February 26, 2025)
An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the customers have customized the block pages.
0
Attacker Value
Unknown
CVE-2024-0313
Disclosure Date: March 14, 2024 (last updated February 26, 2025)
A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately using the temporary bypass to reach out to the Internet for retrieving application and system updates, a remote device could target it and undo the bypass, thereby denying the victim access to the update service, causing it to fail.
0
Attacker Value
Unknown
CVE-2024-0312
Disclosure Date: March 14, 2024 (last updated February 26, 2025)
A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.
0
Attacker Value
Unknown
CVE-2024-0311
Disclosure Date: March 14, 2024 (last updated February 26, 2025)
A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.
0
Attacker Value
Unknown
CVE-2023-4400
Disclosure Date: September 13, 2023 (last updated February 25, 2025)
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.
0
Attacker Value
Unknown
CVE-2022-2310
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.
0