Exploit for #VU46745 Code Injection in Ivanti Server applications


Published: 2020-09-16 | Updated: 2021-01-23

Vulnerability identifier: #VU46745

Vulnerability risk: High

CVSSv3.1: 9.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C]

CVE-ID: CVE-2020-15505

CWE-ID: CWE-94

Exploitation vector: Network

Exploits in database: 2

Impact: Code execution

Vulnerable software:
Enterprise Connector
Client/Desktop applications / Other client software
Reporting Database (RDB)
Client/Desktop applications / Other client software
MobileIron Cloud
Client/Desktop applications / Other client software
Endpoint Manager Mobile (formerly MobileIron Core)
Server applications / IDS/IPS systems, Firewalls and proxy servers
MobileIron Sentry
Server applications / IDS/IPS systems, Firewalls and proxy servers

Vendor: Ivanti