In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target user's username in an HTTP payload in order to retrieve a key/token and use it to access/update objects belonging to other users. Such objects could be user profiles, tickets, incidents, etc.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T18:12:39.572Z

Reserved: 2017-07-19T00:00:00

Link: CVE-2017-11463

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-12-11T06:29:00.223

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-11463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.