Description
The Ivanti Connect Secure and Ivanti Policy Secure have an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get administrative access to the system.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure
References
Related Vulnerabilities
WordPress Plugin WooCommerce-GloBee Payment Gateway Security Bypass (1.1.1)
OpenSSL Improper Input Validation Vulnerability (CVE-2014-3513)
Oracle Application Server CVE-2008-3986 Vulnerability (CVE-2008-3986)
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-19520)