CVE-2022-35259: High severity ivanti endpoint manager (epm) vulnerability
XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35259?
The severity of CVE-2022-35259 is high with a CVSS score of 7.8.
How does XML Injection with Endpoint Manager 2022.3 and below work?
XML Injection with Endpoint Manager 2022.3 and below allows an attacker to inject malicious XML code into the application, which can cause a download of a malicious file to run and possibly execute to gain unauthorized privileges.
Which version of Ivanti Endpoint Manager is affected by CVE-2022-35259?
Ivanti Endpoint Manager versions up to and including 2022.3 are affected by CVE-2022-35259.
How can I fix CVE-2022-35259?
To fix CVE-2022-35259, update Ivanti Endpoint Manager to a version higher than 2022.3.
Where can I find more information about CVE-2022-35259?
More information about CVE-2022-35259 can be found at this link: https://forums.ivanti.com/s/article/Security-Advisory-for-Ivanti-Endpoint-Manager-Client-CVE-2022-35259?language=en_US