Description
The Ivanti Connect Secure and Ivanti Policy Secure have an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get administrative access to the system.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-1147)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13674)
Liferay Portal CVE-2024-25148 Vulnerability (CVE-2024-25148)
Lighttpd Other Vulnerability (CVE-2011-4362)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-2505)