An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 31 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti zero Trust Access Gateway
CPEs cpe:2.3:a:ivanti:zero_trust_access:22.6:r1.3:*:*:*:*:*:* cpe:2.3:a:ivanti:zero_trust_access_gateway:22.6:r1.3:*:*:*:*:*:*
Vendors & Products Ivanti zero Trust Access
Ivanti zero Trust Access Gateway

Fri, 09 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-05-09T18:26:09.386Z

Reserved: 2024-01-04T01:04:06.574Z

Link: CVE-2024-22024

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.846Z

cve-icon NVD

Status : Modified

Published: 2024-02-13T04:15:07.943

Modified: 2025-10-31T16:35:28.557

Link: CVE-2024-22024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.