A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-01-12 17:15
Updated : 2024-06-10 16:21
NVD link : CVE-2024-21887
Mitre link : CVE-2024-21887
CVE.ORG link : CVE-2024-21887
JSON object : View
Products Affected
ivanti
- connect_secure
- policy_secure
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')