Draft in the CWE catalog · 2 CVEs mapped
The product adds hooks to user-accessible API functions, but it does not properly validate the arguments. This could lead to resultant vulnerabilities.
A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.
A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.