PT-2024-3987 · Ivanti · Ivanti Epm+1

Published

2024-03-27

·

Updated

2024-11-18

·

CVE-2024-29830

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti EPM versions 2022 SU5 and prior
Description The issue is related to an unspecified SQL Injection vulnerability in the Core server of Ivanti EPM, allowing an authenticated attacker within the same network to execute arbitrary code. This vulnerability is also associated with the GetLogFileRulesNameUniqueSQL method in Ivanti Endpoint Manager, which fails to protect the SQL query structure, potentially enabling a remote attacker to execute arbitrary code using a specially crafted query.
Recommendations For Ivanti EPM versions 2022 SU5 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-04402
CVE-2024-29830
ZDI-24-513

Affected Products

Ivanti Epm
Ivanti Endpoint Manager