CVE-2024-29846: SQL Injection
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29846?
CVE-2024-29846 is classified as a critical SQL Injection vulnerability that can lead to arbitrary code execution.
How do I fix CVE-2024-29846?
To fix CVE-2024-29846, upgrade to a version of Ivanti Endpoint Manager (EPM) that is later than 2022 SU5.
Who is affected by CVE-2024-29846?
CVE-2024-29846 affects authenticated users of Ivanti Endpoint Manager versions 2022 and prior within the same network.
What types of attacks can be executed using CVE-2024-29846?
An attacker can leverage CVE-2024-29846 to execute arbitrary SQL commands, potentially gaining unauthorized access to data.
Is network isolation sufficient to mitigate CVE-2024-29846?
While network isolation may limit exposure, it does not fully mitigate the risk, as the vulnerability can be exploited by any authenticated user on the network.