Vulnerabilities > CVE-2018-15591 - Exposure of Resource to Wrong Sphere vulnerability in Ivanti Workspace Control

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
ivanti
CWE-668

Summary

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.

Common Weakness Enumeration (CWE)