Back

CRITICAL

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution

Published Sep 10, 2024

Description

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ivanti
Published Sep 10, 2024
Updated Sep 12, 2024
Reserved Aug 26, 2024
CISA Vulnrichment
Updated Sep 11, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ivanti
Published Sep 10, 2024
Updated Sep 12, 2024
Exploited since n/a
EUVD-2024-49005