CVE-2024-22024

HIGH WAF: High
CVSS 8.3 Published: 2024-02-13
CWE-611 CWE-611

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE
XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
ivanticonnect_secure9.1
ivanticonnect_secure9.1
ivanticonnect_secure9.1
ivanticonnect_secure22.4
ivanticonnect_secure22.5
ivanticonnect_secure22.5
ivantipolicy_secure22.5
ivantizero_trust_access_gateway22.6

References

Back to CVE Database