Executive brief
A remote code execution vulnerability exists in multiple Ivanti MobileIron products, including Core & Connector, Sentry, and the Monitor and Reporting Database. The flaw allows unauthenticated attackers to execute arbitrary code via unspecified vectors, reportedly involving Hessian-based Java deserialization.
Affected products
- Ivanti MobileIron Core & Connector 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0, 10.6.0.0
- Ivanti MobileIron Sentry 9.7.2 and earlier, 9.8.0
- Ivanti MobileIron Monitor and Reporting Database (RDB) 2.0.0.1 and earlier
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed