First published: Fri Apr 05 2019(Updated: )
An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resetting the session context.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Workspace Control | <10.3.90.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-10885 is high with a CVSS score of 7.8.
Local authenticated users with low privileges can bypass security features in Ivanti Workspace Control before version 10.3.90.0.
Update Ivanti Workspace Control to version 10.3.90.0 or later to address this vulnerability.
You can find more information about CVE-2019-10885 on the following references: http://packetstormsecurity.com/files/156792/Ivanti-Workspace-Manager-Security-Bypass.html, https://community.ivanti.com/docs/DOC-74552
The CWE ID of CVE-2019-10885 is 264.