XXE in Ivanti Connect Secure, Policy Secure and Neurons (CVE-2024-22024)
Description
The Ivanti Connect Secure, Policy Secure Gate and Neurons have an XXE vulnerability. This vulnerability allows an attacker to send crafted requests to a web application for extraction of secrets from the file system, server-side request forgery or denial-of-service attacks.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure / Neurons