8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.7
Source: NVD
Description
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
Affected (8)
Products: Ivanti: Connect Secure, Policy Secure, Zero Trust Access Gateway
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.4 r2.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.5 r1.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.6 r1.3 |
References (2)
Source: support@hackerone.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.