CVE-2024-32842: SQL Injection
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32842?
CVE-2024-32842 has a critical severity level due to its potential for remote code execution by an authenticated attacker.
How do I fix CVE-2024-32842?
To fix CVE-2024-32842, ensure you upgrade to Ivanti Endpoint Manager versions that include the security update released after September 2024.
Who is affected by CVE-2024-32842?
CVE-2024-32842 affects users of Ivanti Endpoint Manager versions prior to the 2022 SU6 and the September 2024 update.
What kind of attack can exploit CVE-2024-32842?
CVE-2024-32842 can be exploited through a SQL injection vulnerability, allowing attackers to execute arbitrary code remotely.
Is authentication required to exploit CVE-2024-32842?
Yes, CVE-2024-32842 requires the attacker to have admin privileges for successful exploitation.