SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 9
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*
|
— |
<= 2022
|
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
|
— | — |
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:su1:*:*:*:*:*:*
|
— | — |
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:su2:*:*:*:*:*:*
|
— | — |
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:su3:*:*:*:*:*:*
|
— | — |
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:su3_security_release_1:*:*:*:*:*:*
|
— | — |
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:su4:*:*:*:*:*:*
|
— | — |
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:su4_security_release_1:*:*:*:*:*:*
|
— | — |
|
Ivanti Endpoint_Manager
cpe:2.3:a:ivanti:endpoint_manager:2024:su5:*:*:*:*:*:*
|
— | — |