Vulnerabilities > CVE-2024-21893 - Server-Side Request Forgery (SSRF) vulnerability in Ivanti Connect Secure and Policy Secure

047910
CVSS 8.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
LOW
Availability impact
NONE
network
low complexity
ivanti
CWE-918

Summary

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Common Weakness Enumeration (CWE)