A
n XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:55
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://forums.ivanti.com/s/article/New-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US - Vendor Advisory |
03 Oct 2024, 22:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-703 |
Information
Published : 2024-04-04 20:15
Updated : 2024-11-21 08:55
NVD link : CVE-2024-22023
Mitre link : CVE-2024-22023
CVE.ORG link : CVE-2024-22023
JSON object : View
Products Affected