Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Connect_secure | Ivanti | * | 22.7 (excluding) |
Connect_secure | Ivanti | 22.7 (including) | 22.7 (including) |
Connect_secure | Ivanti | 22.7-r1 (including) | 22.7-r1 (including) |
Connect_secure | Ivanti | 22.7-r1.1 (including) | 22.7-r1.1 (including) |
Connect_secure | Ivanti | 22.7-r1.2 (including) | 22.7-r1.2 (including) |
Connect_secure | Ivanti | 22.7-r1.3 (including) | 22.7-r1.3 (including) |
Connect_secure | Ivanti | 22.7-r1.4 (including) | 22.7-r1.4 (including) |
Connect_secure | Ivanti | 22.7-r1.5 (including) | 22.7-r1.5 (including) |
Connect_secure | Ivanti | 22.7-r2 (including) | 22.7-r2 (including) |
Connect_secure | Ivanti | 22.7-r2.1 (including) | 22.7-r2.1 (including) |
Connect_secure | Ivanti | 22.7-r2.2 (including) | 22.7-r2.2 (including) |
Connect_secure | Ivanti | 22.7-r2.3 (including) | 22.7-r2.3 (including) |