CVE-2020-13769: SQL Injection
Published Nov 16, 2020
·Updated
LDMS/alertlog.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.
Affected Software
1 affected component
Ivanti Endpoint Manager<=2020.1
Event History
Nov 16, 2020
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
Description
Frequently Asked Questions
1
What is CVE-2020-13769?
CVE-2020-13769 is a vulnerability in Ivanti Endpoint Manager through 2020.1 that allows SQL Injection via a /remotecontrolauth/api/device request.
2
How severe is CVE-2020-13769?
CVE-2020-13769 has a severity rating of 8.8 (high).
3
Which software versions are affected by CVE-2020-13769?
Versions of Ivanti Endpoint Manager up to and including 2020.1 are affected by CVE-2020-13769.
4
How can I fix CVE-2020-13769?
To fix CVE-2020-13769, it is recommended to update to a version of Ivanti Endpoint Manager that includes a patch for the vulnerability.
5
Is there any additional information about CVE-2020-13769?
Yes, you can find additional information about CVE-2020-13769 in the Ivanti forums and a detailed advisory by Jumpsec Labs.