An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
History

Fri, 09 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-02-13T04:07:04.355Z

Updated: 2025-05-09T18:26:09.386Z

Reserved: 2024-01-04T01:04:06.574Z

Link: CVE-2024-22024

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.846Z

cve-icon NVD

Status : Modified

Published: 2024-02-13T04:15:07.943

Modified: 2025-05-09T19:15:59.813

Link: CVE-2024-22024

cve-icon Redhat

No data.