CVE-2019-12374: SQL Injection
Published Jun 3, 2019
·Updated
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in Provisioning.Secure.dll.
Affected Software
1 affected component
Ivanti LANDESK Management Suite=10.0.1.168-service_update_5
Event History
Jun 3, 2019
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12374?
CVE-2019-12374 is classified as a critical SQL Injection vulnerability.
2
How do I fix CVE-2019-12374?
To fix CVE-2019-12374, upgrade to a version of Ivanti LANDESK Management Suite that addresses the vulnerability.
3
What software versions are affected by CVE-2019-12374?
CVE-2019-12374 affects Ivanti LANDESK Management Suite version 10.0.1.168 Service Update 5.
4
What kind of vulnerability is CVE-2019-12374?
CVE-2019-12374 is a SQL Injection vulnerability due to improper username sanitization.
5
Where does CVE-2019-12374 exist in the software?
CVE-2019-12374 exists in the Basic Authentication implementation in Provisioning.Secure.dll.