CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-7569

CVSS 9.6v3.1pub. 2024-08-13upd. 2024-09-06

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.

🤖 AI Analysis
How it works

The application in debug mode exposes sensitive configuration data, including OIDC client secret, without requiring any authentication from the attacker. An attacker can remotely access this information over the network by executing an appropriate HTTP request. The obtained OIDC client secret can then be used to impersonate a trusted client application in the OAuth/OIDC authorization process.

Impact

An attacker can obtain the OIDC client secret and potentially bypass authentication mechanisms, which may result in unauthorized access to the system, user account takeover, and compromise of confidentiality, integrity, and availability of data managed by the ITSM system.

Mitigation & patch

Apply patches available from the vendor according to the references (https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2024-7569-CVE-2024-7570). Additionally, it is recommended to rotate the OIDC client secret after applying updates and to disable debug mode in production environments.

Who is affected

Ivanti ITSM (on-prem) and Ivanti Neurons for ITSM in versions 2023.4 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Ivanti Neurons For Itsm

    APP
    Ivanti
    2023.22023.32023.4
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-22462CRITICAL9.8PL ✓same product

Authentication Bypass w Ivanti Neurons for ITSM — dostęp administracyjny bez uwierzytelnienia

CVE-2023-46808CRITICAL9.9PL ✓same product

Ivanti Neurons for ITSM — podatność file upload umożliwiająca zapis plików na serwerze

CVE-2024-7570HIGH8.3same product

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows...

CVE-2024-22059HIGH8.8same product

A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user t...

CVE-2024-22060MEDIUM4.9same product

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authent...