Mail Gateway Flaws Expose Traffic and Internal Access
SEPPMail is more than a filtering layer here. A compromise can expose protected mail flows and give an attacker a foothold inside the network, so patching this box is not just about closing a web flaw.
InfoGuard Labs disclosed seven SEPPMail Secure E-Mail Gateway vulnerabilities at once, covering remote code execution, path traversal, authorization bypass, deserialization, and eval injection. The issues affect the Secure E-Mail Gateway appliance and are fixed across staggered releases from 15.0.2.1 through 15.0.4.
The practical problem is blast radius. A vulnerable gateway can reveal arbitrary mailbox traffic and act as an entry point into the internal network, so some appliances remain exposed until the right 15.0.x fix is in place.