Medium severity5.3NVD Advisory· Published Nov 16, 2020· Updated Jun 17, 2026
CVE-2020-13772
CVE-2020-13772
Description
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
Affected products
3cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <=2020.1.1
- (no CPE)range: <=2020.1.1
- Ivanti/Endpoint Managerdescription
Patches
Vulnerability mechanics
References
2- labs.jumpsec.com/cve-2020-13772-ivanti-uem-system-information-disclosure/nvdExploitThird Party Advisory
- forums.ivanti.com/s/nvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.