CVE-2024-13162: SQL Injection
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13162?
CVE-2024-13162 has a critical severity rating due to its potential for remote code execution by authenticated attackers.
How do I fix CVE-2024-13162?
To mitigate CVE-2024-13162, ensure you apply the security updates provided in the 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update.
Who is affected by CVE-2024-13162?
CVE-2024-13162 affects users of Ivanti Endpoint Manager (EPM) versions prior to the January-2025 Security Updates.
What type of vulnerability is CVE-2024-13162?
CVE-2024-13162 is an SQL injection vulnerability that can lead to remote code execution.
What can attackers gain from exploiting CVE-2024-13162?
An attacker exploiting CVE-2024-13162 can achieve remote code execution with administrative privileges.