CVE-2024-22059: SQL Injection
Published May 31, 2024
·Updated
A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the underlying database. This may also lead to DoS.
Affected Software
2 affected components
Ivanti Neurons for ITSM
Ivanti Neurons for ITSM<2023.3
Event History
May 31, 2024
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22059?
CVE-2024-22059 is a high severity SQL injection vulnerability that allows unauthorized access to the underlying database.
2
How do I fix CVE-2024-22059?
To fix CVE-2024-22059, apply the latest security patches provided by Ivanti for Neurons for ITSM.
3
Who is affected by CVE-2024-22059?
CVE-2024-22059 affects any remote authenticated user of Ivanti Neurons for ITSM.
4
What type of vulnerabilities can result from CVE-2024-22059?
CVE-2024-22059 can lead to unauthorized reading, modification, or deletion of data in the database, and may also cause Denial of Service (DoS) attacks.
5
Is CVE-2024-22059 known to be exploited in the wild?
As of now, there are no confirmed reports of CVE-2024-22059 being actively exploited in the wild.