Ivanti.Connect.Secure.saml-sso.XXE

description-logoDescription

This indicates an attack attempt to exploit an External Entity Injection Vulnerability in Ivanti Connect Secure, Ivanti Policy Secure and ZTA Gateways.
A remote authenticated attacker could exploit this vulnerability by sending malicious XML data to the target server. Successful exploitation could result in arbitrary code within the context of the application.

affected-products-logoAffected Products

Ivanti Connect Secure versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and 22.5R2.2
Ivanti Policy Secure version 22.5R1.1
Ivanti ZTA version 22.6R1.3

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-03-13 27.748 Default_action:pass:drop
2024-03-04 27.742