漏洞描述 由于 Apache HTTPD 配置限制不足,Ivanti MobileIron Sentry 版本 9.18.0 及更低版本中的 MICS管理门户中存在安全漏洞,该漏洞可绕过管理界面上的身份验证控制,执行任意命令,通过该漏洞可以获取服务器权限。
相关漏洞推荐 Ivanti Pulse Connect Secure VPN /dana-na/auth/saml-sso.cgi XML 外部实体注入漏洞(CVE-2024-22024) POC CVE-2025-22457: Ivanti Connect Secure - Stack-based Buffer Overflow POC CVE-2020-15505: MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution POC CVE-2021-30497: Ivanti Avalanche 6.3.2 - Local File Inclusion POC CVE-2021-44529: Ivanti EPM Cloud Services Appliance Code Injection POC CVE-2023-32563: Ivanti Avalanche - Remote Code Execution POC CVE-2023-35078: Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass POC CVE-2023-35082: MobileIron Core - Remote Unauthenticated API Access POC CVE-2023-38035: Ivanti Sentry - Authentication Bypass POC CVE-2023-46805: Ivanti ICS - Authentication Bypass POC CVE-2024-13159: Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcardRecursive POC CVE-2024-13160: Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcard POC CVE-2024-13161: Ivanti EPM - Credential Coercion Vulnerability in GetHashForSingleFile