Description
Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core, is vulnerable to API Authentication bypass vulnerability. An attacker could exploit this vulnerability to access users' personally identifiable information and make changes to the server.
Remediation
Upgrade to the latest version of Ivanti EPMM
References
CVE-2023-35078 - Remote Unauthenticated API Access Vulnerability
CVE-2023-35082 - Remote Unauthenticated API Access Vulnerability
CVE-2023-35082 - MobileIron Core Unauthenticated API Access Vulnerability
Related Vulnerabilities
Oracle JRE CVE-2013-2438 Vulnerability (CVE-2013-2438)
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4452)
Sqlite CVE-2021-36690 Vulnerability (CVE-2021-36690)
WordPress Plugin Image Source Control Security Bypass (2.3.0)
WordPress Plugin Data Tables Generator by Supsystic Security Bypass (1.10.25)