An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
The product dereferences a pointer that it expects to be valid but is NULL.
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.