First published: Mon Jun 03 2019(Updated: )
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in Provisioning.Secure.dll.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti LANDESK Management Suite | =10.0.1.168-service_update_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12374 is classified as a critical SQL Injection vulnerability.
To fix CVE-2019-12374, upgrade to a version of Ivanti LANDESK Management Suite that addresses the vulnerability.
CVE-2019-12374 affects Ivanti LANDESK Management Suite version 10.0.1.168 Service Update 5.
CVE-2019-12374 is a SQL Injection vulnerability due to improper username sanitization.
CVE-2019-12374 exists in the Basic Authentication implementation in Provisioning.Secure.dll.