An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
The application in debug mode exposes sensitive configuration data, including OIDC client secret, without requiring any authentication from the attacker. An attacker can remotely access this information over the network by executing an appropriate HTTP request. The obtained OIDC client secret can then be used to impersonate a trusted client application in the OAuth/OIDC authorization process.
An attacker can obtain the OIDC client secret and potentially bypass authentication mechanisms, which may result in unauthorized access to the system, user account takeover, and compromise of confidentiality, integrity, and availability of data managed by the ITSM system.
Apply patches available from the vendor according to the references (https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2024-7569-CVE-2024-7570). Additionally, it is recommended to rotate the OIDC client secret after applying updates and to disable debug mode in production environments.
Ivanti ITSM (on-prem) and Ivanti Neurons for ITSM in versions 2023.4 and earlier
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HIvanti Neurons For Itsm
APPIvanti2023.22023.32023.4
Related vulnerabilities
Authentication Bypass w Ivanti Neurons for ITSM — dostęp administracyjny bez uwierzytelnienia
Ivanti Neurons for ITSM — podatność file upload umożliwiająca zapis plików na serwerze
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows...
A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user t...
An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authent...