A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
30 Oct 2025, 20:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21893 - US Government Resource |
21 Oct 2025, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2024-01-31 18:15
Updated : 2025-10-30 20:40
NVD link : CVE-2024-21893
Mitre link : CVE-2024-21893
CVE.ORG link : CVE-2024-21893
JSON object : View
Products Affected
ivanti
- policy_secure
- neurons_for_zero-trust_access
- connect_secure
CWE
CWE-918
Server-Side Request Forgery (SSRF)
