Home
CRITICAL: 9.1 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
2024 September Security Update (custom) before 2024 September Security Update
affected
2022 SU6 (custom) before 2022 SU6
affected
Description
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Product status
2024 September Security Update (custom) before 2024 September Security Update
2022 SU6 (custom) before 2022 SU6
References
forums.ivanti.com/...eptember-2024-for-EPM-2024-and-EPM-2022