Vulnerability Description
In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target user's username in an HTTP payload in order to retrieve a key/token and use it to access/update objects belonging to other users. Such objects could be user profiles, tickets, incidents, etc.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Endpoint Manager | 2016.4 |
Related Weaknesses (CWE)
References
- https://community.ivanti.com/docs/DOC-66252
- https://gist.github.com/lazyhack3r/439e92419c552b5dc82b2f5e832c8bfbIssue TrackingThird Party Advisory
- https://community.ivanti.com/docs/DOC-66252
- https://gist.github.com/lazyhack3r/439e92419c552b5dc82b2f5e832c8bfbIssue TrackingThird Party Advisory
FAQ
What is CVE-2017-11463?
CVE-2017-11463 is a vulnerability with a CVSS score of 8.8 (HIGH). In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. I...
How severe is CVE-2017-11463?
CVE-2017-11463 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11463?
Check the references section above for vendor advisories and patch information. Affected products include: Ivanti Endpoint Manager.