VYPR

Service Manager

by Ivanti

CVEs (2)

  • CVE-2020-12441CriAug 6, 2020
    risk 0.64cvss 9.8epss 0.04

    Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.

  • CVE-2021-38560MedFeb 1, 2022
    risk 0.40cvss 6.1epss 0.03

    Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.