VendorsIvantineurons_for_itsm2023.2
Vulnerabilities

Ivanti Neurons for ITSM 2023.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-7569
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
Published 2024-08-13 · Analyzed
9.8EPSS 0.017
CVE-2024-7570
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.
Published 2024-08-13 · Analyzed
8.3EPSS 0.006