An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
CVSS Details
- CVSS 3.1 Base Score: 8.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Pulse Secure Pulse Connect Secure | — | Update Ivanti Connect Secure to version 22.6R2.2Update Ivanti Connect Secure to version 22.3R1.1Update Ivanti Connect Secure to version 22.1R6.1Update Ivanti Connect Secure to version 22.4R2.3Update Ivanti Connect Secure to version 22.5R2.3Update Ivanti Connect Secure to version 9.1R18.4Update Ivanti Connect Secure to version 22.2R4.1 | Feb 13, 2024 | Feb 8, 2024 |
| Pulse Secure Pulse Policy Secure | — | Update to patched version | Feb 12, 2024 | Feb 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub