Description
Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core, is vulnerable to API Authentication bypass vulnerability. An attacker could exploit this vulnerability to access users' personally identifiable information and make changes to the server.
Remediation
Upgrade to the latest version of Ivanti EPMM
References
CVE-2023-35078 - Remote Unauthenticated API Access Vulnerability
CVE-2023-35082 - Remote Unauthenticated API Access Vulnerability
CVE-2023-35082 - MobileIron Core Unauthenticated API Access Vulnerability
Related Vulnerabilities
Magento Insufficient Session Expiration Vulnerability (CVE-2021-21032)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-2853)
WordPress Plugin Ultimeter Security Bypass (1.9.2)
Oracle Database Server Other Vulnerability (CVE-2005-3440)
WordPress Plugin Thrive Clever Widgets Security Bypass (1.56)