An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-02-13T04:07:04.355Z

Updated: 2024-08-01T22:35:34.846Z

Reserved: 2024-01-04T01:04:06.574Z

Link: CVE-2024-22024

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-02-13T04:15:07.943

Modified: 2024-02-13T15:15:32.193

Link: CVE-2024-22024

cve-icon Redhat

No data.