An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.
References
Link | Resource |
---|---|
https://gist.github.com/bhyahoo/4772330b20057a271f77e690bc70f928 | Third Party Advisory |
https://www.ivanti.com/releases | Release Notes |
https://gist.github.com/bhyahoo/4772330b20057a271f77e690bc70f928 | Third Party Advisory |
https://www.ivanti.com/releases | Release Notes |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/bhyahoo/4772330b20057a271f77e690bc70f928 - Third Party Advisory | |
References | () https://www.ivanti.com/releases - Release Notes |
25 Sep 2023, 17:09
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-611 | |
CPE | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:* |
|
First Time |
Ivanti
Ivanti endpoint Manager |
|
References | (MISC) https://www.ivanti.com/releases - Release Notes | |
References | (MISC) https://gist.github.com/bhyahoo/4772330b20057a271f77e690bc70f928 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
21 Sep 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-21 21:15
Updated : 2024-11-21 08:13
NVD link : CVE-2023-38343
Mitre link : CVE-2023-38343
CVE.ORG link : CVE-2023-38343
JSON object : View
Products Affected
ivanti
- endpoint_manager
CWE
CWE-611
Improper Restriction of XML External Entity Reference