SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
2024-11-13T02:15:17.850
2025-05-01T18:01:46.330
Analyzed
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | endpoint_manager | < 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2022 | Yes |
Application | ivanti | endpoint_manager | 2024 | Yes |