Ryan Emmons, staff security researcher at Rapid7, found the issue earlier this year and reported it to Ivanti on 15 August.