A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-01-31 18:15
Updated : 2024-07-03 01:46
NVD link : CVE-2024-21893
Mitre link : CVE-2024-21893
CVE.ORG link : CVE-2024-21893
JSON object : View
Products Affected
ivanti
- neurons_for_zero-trust_access
- connect_secure
- policy_secure
CWE
CWE-918
Server-Side Request Forgery (SSRF)