CVE-2020-13772

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2020
Last modified:
21/11/2020

Description

In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* 2020.1.1 (including)