First published: Fri May 31 2024(Updated: )
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager (EPM) | <2022 | |
Ivanti Endpoint Manager (EPM) | =2022 | |
Ivanti Endpoint Manager (EPM) | =2022-su1 | |
Ivanti Endpoint Manager (EPM) | =2022-su2 | |
Ivanti Endpoint Manager (EPM) | =2022-su3 | |
Ivanti Endpoint Manager (EPM) | =2022-su4 | |
Ivanti Endpoint Manager (EPM) | =2022-su5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29846 is classified as a critical SQL Injection vulnerability that can lead to arbitrary code execution.
To fix CVE-2024-29846, upgrade to a version of Ivanti Endpoint Manager (EPM) that is later than 2022 SU5.
CVE-2024-29846 affects authenticated users of Ivanti Endpoint Manager versions 2022 and prior within the same network.
An attacker can leverage CVE-2024-29846 to execute arbitrary SQL commands, potentially gaining unauthorized access to data.
While network isolation may limit exposure, it does not fully mitigate the risk, as the vulnerability can be exploited by any authenticated user on the network.