Description
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48468 | An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information. |
References
History
Fri, 06 Sep 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:ivanti:neurons_for_itsm:2023.2:*:*:*:*:*:*:* cpe:2.3:a:ivanti:neurons_for_itsm:2023.3:*:*:*:*:*:*:* |
Wed, 14 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti
Ivanti neurons For Itsm |
|
| CPEs | cpe:2.3:a:ivanti:neurons_for_itsm:2023.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Ivanti
Ivanti neurons For Itsm |
|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information. | |
| Weaknesses | CWE-215 CWE-922 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ivanti
Published:
Updated: 2024-08-16T04:02:04.140Z
Reserved: 2024-08-06T19:15:59.879Z
Link: CVE-2024-7569
Updated: 2024-08-14T13:48:08.837Z
Status : Analyzed
Published: 2024-08-13T19:15:16.443
Modified: 2024-09-06T21:57:23.037
Link: CVE-2024-7569
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD