Description
The Ivanti Connect Secure and Ivanti Policy Secure have an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get administrative access to the system.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure
References
Related Vulnerabilities
Joomla Improper Authentication Vulnerability (CVE-2014-6632)
Craft CMS Missing Encryption of Sensitive Data Vulnerability (CVE-2018-20465)
MySQL CVE-2019-2691 Vulnerability (CVE-2019-2691)
Moodle Improper Encoding or Escaping of Output Vulnerability (CVE-2021-40694)
Oracle Database Server CVE-2008-2592 Vulnerability (CVE-2008-2592)