Description
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
2024 SU3 SR1
2022 SU8 SR2
References
forums.ivanti.com/...vanti-Endpoint-Manager-EPM-October-2025