First published: Mon Nov 16 2020(Updated: )
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager | <=2020.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13772 is a vulnerability in Ivanti Endpoint Manager that allows an attacker to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
CVE-2020-13772 has a severity rating of 5.3 (medium).
Ivanti Endpoint Manager versions up to and including 2020.1.1 are affected by CVE-2020-13772.
To fix CVE-2020-13772, upgrade to a version of Ivanti Endpoint Manager that is higher than 2020.1.1.
You can find more information about CVE-2020-13772 in the Ivanti Endpoint Manager forums (link: https://forums.ivanti.com/s/) and in the Jumpsec Labs advisory (link: https://labs.jumpsec.com/cve-2020-13772-ivanti-uem-system-information-disclosure/).