CVE Vulnerabilities

CVE-2017-11463

Published: Dec 11, 2017 | Modified: Mar 28, 2018
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target users username in an HTTP payload in order to retrieve a key/token and use it to access/update objects belonging to other users. Such objects could be user profiles, tickets, incidents, etc.

Affected Software

Name Vendor Start Version End Version
Endpoint_manager Ivanti 2016.4 (including) 2016.4 (including)
Endpoint_manager Ivanti 2017.1 (including) 2017.1 (including)
Endpoint_manager Ivanti 2017.3 (including) 2017.3 (including)

References