In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Endpoint_manager | Ivanti | * | 2020.1.1 (including) |