An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
2024-09-12T02:15:02.730
2024-09-12T22:35:04.037
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | endpoint_manager | < 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2024 | Yes |