Vulnerabilities > Ivanti > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-01 CVE-2021-38560 Cross-site Scripting vulnerability in Ivanti Service Manager 2021.1
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
network
low complexity
ivanti CWE-79
6.1
2022-01-10 CVE-2022-21823 Insecure Storage of Sensitive Information vulnerability in Ivanti Workspace Control
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
local
low complexity
ivanti CWE-922
5.5
2021-08-16 CVE-2021-22933 Path Traversal vulnerability in multiple products
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
network
low complexity
pulsesecure ivanti CWE-22
6.5
2021-08-16 CVE-2021-22936 Cross-site Scripting vulnerability in multiple products
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
network
low complexity
pulsesecure ivanti CWE-79
6.1
2020-11-16 CVE-2020-13773 Cross-site Scripting vulnerability in Ivanti Endpoint Manager
Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx, and /LDMS/query_browsecomp.aspx.
network
low complexity
ivanti CWE-79
5.4
2020-11-16 CVE-2020-13772 Unspecified vulnerability in Ivanti Endpoint Manager
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
network
low complexity
ivanti
5.3
2020-10-28 CVE-2020-8262 Cross-site Scripting vulnerability in multiple products
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.
network
low complexity
pulsesecure ivanti CWE-79
6.1
2020-10-28 CVE-2020-8261 Classic Buffer Overflow vulnerability in multiple products
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
network
low complexity
pulsesecure ivanti CWE-120
4.3
2020-09-30 CVE-2020-8256 XXE vulnerability in multiple products
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
network
low complexity
pulsesecure ivanti CWE-611
4.9
2020-09-30 CVE-2020-8238 Cross-site Scripting vulnerability in multiple products
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).
network
low complexity
pulsesecure ivanti CWE-79
6.1