PT-2017-12032 · Ivanti · Ivanti Service Desk
Published
2017-12-11
·
Updated
2018-03-28
·
CVE-2017-11463
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti Service Desk versions 2016.3 through 2017.3
Description
The issue allows a normal user to send requests to a specific URI with the target user's
username in an HTTP payload to retrieve a key/token and use it to access or update objects belonging to other users, such as user profiles, tickets, and incidents.Recommendations
For Ivanti Service Desk versions 2016.3 through 2017.3, consider restricting access to the specific URI that allows referencing and updating of objects belonging to other users until a patch is available. As a temporary workaround, limit the ability of normal users to send requests with the target user's
username in the HTTP payload to prevent unauthorized access to other users' objects.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Service Desk