Ivanti Policy Secure
cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*
- < 22.6R1
- < 9.1R18x
An arbitrary file read vulnerability has been identified in Ivanti Policy Secure versions prior to 22.6R1. This issue allows authenticated administrators to read arbitrary files by sending a maliciously crafted web request.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.
Users can upgrade to Ivanti Policy Secure version 22.6R1 to address this vulnerability. For those on the 9.1Rx version, an upgrade to 9.1R18x, tentatively scheduled for late January 2024, is recommended.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.