In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
References
Link Resource
https://forums.ivanti.com/s/ Permissions Required Vendor Advisory
https://labs.jumpsec.com/cve-2020-13772-ivanti-uem-system-information-disclosure/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-11-16T15:24:46

Updated: 2020-11-16T15:24:46

Reserved: 2020-06-02T00:00:00


Link: CVE-2020-13772

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-11-16T16:15:14.133

Modified: 2020-11-21T03:35:52.550


Link: CVE-2020-13772

JSON object: View

cve-icon Redhat Information

No data.