CVE-2016-6597: Sophos Mobile Control Eas Proxy
High severity, CVSS 8.6. EPSS: 4.5% chance of exploitation in the next 30 days.
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.
Affected products
- Sophos Mobile Control Eas Proxy: up to and including 3.5.0.3
Published 2016-08-10. Last modified 2026-06-17.