Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
affected
2024 November Security Update (custom)
unaffected
2022 SU6 November Security Update (custom)
unaffected
Description
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
2024 November Security Update (custom)
2022 SU6 November Security Update (custom)
References
forums.ivanti.com/...November-2024-for-EPM-2024-and-EPM-2022