In /ldclient/ldprov.cgi in Ivanti Endpoint Manager up to and including 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ivanti endpoint manager |