PT-2024-4021 · Ivanti · Ivanti Neurons For Itsm

Published

2024-05-20

·

Updated

2024-07-03

·

CVE-2024-22059

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ivanti Neurons for ITSM (affected versions not specified)
Description: The issue is related to a SQL injection vulnerability in the web component of Ivanti Neurons for ITSM, due to inadequate protection of the SQL query structure. This vulnerability can be exploited by a remote attacker to read, modify, or delete arbitrary files and potentially cause a denial of service using a specially crafted query. The vulnerability may allow an attacker to access and manipulate information in the underlying database.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-04454
BDU:2024-04472
CVE-2024-22059

Affected Products

Ivanti Neurons For Itsm