An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.
References
Link | Resource |
---|---|
https://gist.github.com/bhyahoo/4772330b20057a271f77e690bc70f928 | Third Party Advisory |
https://www.ivanti.com/releases | Release Notes |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-09-21 21:15
Updated : 2023-09-25 17:09
NVD link : CVE-2023-38343
Mitre link : CVE-2023-38343
CVE.ORG link : CVE-2023-38343
JSON object : View
Products Affected
ivanti
- endpoint_manager
CWE
CWE-611
Improper Restriction of XML External Entity Reference