VYPR
Medium severity4.9NVD Advisory· Published Jul 12, 2025· Updated Jun 17, 2026

CVE-2023-39339

CVE-2023-39339

Description

A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary file read via a maliciously crafted web request.

Affected products

4
  • cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*range: <22.6
    • cpe:2.3:a:ivanti:policy_secure:22.6:-:*:*:*:*:*:*
    • (no CPE)range: <22.6R1
    • (no CPE)range: 22.6R1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.