Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Ivanti Connect Secure (9.x, 22.x) 및 Ivanti Policy Secure (9.x, 22.x)의 웹 구성요소에 존재하는 명령 인젝션 취약점으로 인해 인증된 관리자가 특수하게 조작된 요청을 전송하고 어플라이언스에서 임의의 명령을 실행할 수 있습니다.
Ivanti Connect Secure (9.x, 22.x) 및 Ivanti Policy Secure (9.x, 22.x)의 웹 구성요소에 존재하는 명령 인젝션 취약점으로 인해 인증된 관리자가 특수하게 조작된 요청을 전송하고 어플라이언스에서 임의의 명령을 실행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.