Upstream information
Description
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
CNA (HackerOne) | National Vulnerability Database | |
---|---|---|
Base Score | 8.2 | 8.2 |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Attack Vector | Network | Network |
Attack Complexity | Low | Low |
Privileges Required | None | None |
User Interaction | None | None |
Scope | Unchanged | Unchanged |
Confidentiality Impact | High | High |
Integrity Impact | Low | Low |
Availability Impact | None | None |
CVSSv3 Version | 3 | 3.1 |
SUSE Timeline for this CVE
CVE page created: Wed Jan 31 21:00:25 2024CVE page last modified: Sat Nov 30 11:54:57 2024