An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
2024-05-31T18:15:11.017
2024-11-21T09:08:24.637
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | endpoint_manager | < 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |