A code injection vulnerability in the Ivanti EPM Cloud...
Critical severity
Unreviewed
Published
Dec 9, 2021
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Dec 8, 2021
Published to the GitHub Advisory Database
Dec 9, 2021
Last updated
Feb 3, 2023
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
References