CVE-2024-32845: SQL Injection
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32845?
CVE-2024-32845 is considered critical due to its potential to allow remote code execution by an authenticated attacker.
How do I fix CVE-2024-32845?
To fix CVE-2024-32845, it is recommended to upgrade to the latest version of Ivanti Endpoint Manager released after the 2024 September update.
Who is affected by CVE-2024-32845?
CVE-2024-32845 affects users of Ivanti Endpoint Manager versions prior to the 2024 September update and all 2022 versions before SU6.
What type of vulnerability is CVE-2024-32845?
CVE-2024-32845 is a SQL injection vulnerability that can lead to remote code execution.
Can CVE-2024-32845 be exploited remotely?
Yes, CVE-2024-32845 can be exploited remotely by an authenticated attacker with admin privileges.