Learn about CVE-2017-11463, a vulnerability in Ivanti Service Desk versions 2016.3 to 2017.3 allowing unauthorized access to objects. Find mitigation steps and prevention measures here.
A vulnerability known as Unrestricted Direct Object Reference in Ivanti Service Desk (previously LANDESK Management Suite) versions 2016.3 to 2017.3 allows unauthorized users to access and modify objects belonging to other users.
Understanding CVE-2017-11463
This CVE involves a security flaw in Ivanti Service Desk that enables users to manipulate objects not assigned to them, potentially compromising sensitive data.
What is CVE-2017-11463?
Between versions 2016.3 and 2017.3 of Ivanti Service Desk, the Unrestricted Direct Object Reference vulnerability permits users to reference or update objects that are not their own, leading to unauthorized access and modification.
The Impact of CVE-2017-11463
This vulnerability allows regular users to exploit the system, retrieve sensitive information, and make unauthorized changes to various objects within the service desk platform.
Technical Details of CVE-2017-11463
Ivanti Service Desk vulnerability details and exploitation mechanisms.
Vulnerability Description
The flaw in Ivanti Service Desk versions 2016.3 to 2017.3 enables users to send requests with a target user's username in the HTTP payload, granting access to keys or tokens for unauthorized object manipulation.
Affected Systems and Versions
Exploitation Mechanism
Unauthorized users can send requests to specific URIs with target user information, allowing them to access and modify objects like user profiles, tickets, and incidents belonging to other users.
Mitigation and Prevention
Steps to mitigate and prevent the exploitation of CVE-2017-11463.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates