Ivanti.EPM.CSA.HTTP.Cookie.Remote.Code.Injection
Description
This indicates an attack attempt to exploit a Remote Code Injection Vulnerability in Ivanti EPM CSA.
This vulnerability is due to improper input validation for an crafted HTTP request. A remote attacker could exploit this vulnerability by sending a crafted HTTP request to the target server. Successfully exploiting this vulnerability could result in arbitrary code execution in the context of the system.
Affected Products
Ivanti Endpoint Manager Cloud Serices Appliance version 4.5 and prior
Ivanti Endpoint Manager Cloud Serices Appliance version 4.6
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://forums.ivanti.com/s/article/SA-2021-12-02
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |