PT-2024-4036 · Ivanti · Ivanti Neurons For Itsm

Published

2024-05-20

·

Updated

2024-08-25

·

CVE-2024-22060

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Neurons for ITSM (affected versions not specified)
Description The issue is related to an unrestricted file upload vulnerability in the web component of Ivanti Neurons for ITSM. This vulnerability allows a remote, authenticated, high-privileged user to write arbitrary files into sensitive directories of the ITSM server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-04472
CVE-2024-22060

Affected Products

Ivanti Neurons For Itsm