File Upload Vulnerability in Ivanti ITSM Before 2023.4 Allows Remote File Writes and Command Execution
CVE-2023-46808
9.9CRITICAL
What is CVE-2023-46808?
An authenticated remote file upload vulnerability in Ivanti ITSM versions before 2023.4 permits an authenticated user to write arbitrary files to the server. Exploitation of this vulnerability may enable an attacker to execute commands within the context of a non-root user, potentially compromising the security of sensitive data and the overall system integrity. Organizations using affected versions are advised to apply necessary updates and assess their security measures.
Affected Version(s)
ITSM 2023.3