First published: Wed Nov 13 2024(Updated: )
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager (EPM) | <2024 November Security Update<2022 SU6 November Security Update | |
Ivanti Endpoint Manager (EPM) | <2022 | |
Ivanti Endpoint Manager (EPM) | =2022 | |
Ivanti Endpoint Manager (EPM) | =2022-su1 | |
Ivanti Endpoint Manager (EPM) | =2022-su2 | |
Ivanti Endpoint Manager (EPM) | =2022-su3 | |
Ivanti Endpoint Manager (EPM) | =2022-su4 | |
Ivanti Endpoint Manager (EPM) | =2022-su5 | |
Ivanti Endpoint Manager (EPM) | =2024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32847 is considered critical due to its potential for remote code execution.
To mitigate CVE-2024-32847, upgrade to the latest version of Ivanti Endpoint Manager that includes the November 2024 security update.
CVE-2024-32847 can be exploited by remote authenticated attackers who have admin privileges.
The impact of CVE-2024-32847 includes the potential for an attacker to achieve remote code execution on the affected system.
Ivanti Endpoint Manager versions prior to the 2024 November Security Update and 2022 SU6 November Security Update are affected by CVE-2024-32847.