An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
2024-09-12T02:15:02.567
2024-09-12T22:35:03.333
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | endpoint_manager | < 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2024 | Yes |