Description
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
Scores
CVSS v3
9.6
EPSS
0.0747
EPSS Percentile
91.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-922
CWE-215
Status
published
Products (3)
ivanti/neurons_for_itsm
2023.2
ivanti/neurons_for_itsm
2023.3
ivanti/neurons_for_itsm
2023.4
Published
Aug 13, 2024
Tracked Since
Feb 18, 2026