CVE-2019-10885: High severity ivanti workspace control vulnerability
An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resetting the session context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10885?
The severity of CVE-2019-10885 is high with a CVSS score of 7.8.
What is the impact of CVE-2019-10885?
Local authenticated users with low privileges can bypass security features in Ivanti Workspace Control before version 10.3.90.0.
How can I fix CVE-2019-10885?
Update Ivanti Workspace Control to version 10.3.90.0 or later to address this vulnerability.
Where can I find more information about CVE-2019-10885?
You can find more information about CVE-2019-10885 on the following references: http://packetstormsecurity.com/files/156792/Ivanti-Workspace-Manager-Security-Bypass.html, https://community.ivanti.com/docs/DOC-74552
What is the CWE ID of CVE-2019-10885?
The CWE ID of CVE-2019-10885 is 264.