PT-2024-27510 · Ivanti · Ivanti Epm

Published

2024-07-17

·

Updated

2025-07-10

·

CVE-2024-37381

CVSS v3.1

8.4

High

VectorAV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti EPM 2024 flat
Description The issue is related to an unspecified SQL Injection flaw in the core server, allowing an authenticated attacker within the same network to execute arbitrary code.
Recommendations For Ivanti EPM 2024 flat, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-37381

Affected Products

Ivanti Epm