Where
-Infinity
0
Severity
9.8
EPSS
52.91%
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

First published (updated )
Severity
9.8
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

First published (updated )
Severity
9.8
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

1 / 2
Source: NVD
First published (updated )
Severity
9.6
SQL Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.

First published (updated )
Severity
9.6
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

First published (updated )
Severity
8.8
EPSS
99.88%
SQL Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8.8
EPSS
64.39%
SQL Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8.8
EPSS
99.86%
SQL Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8.8
EPSS
71.69%
SQL Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8.8
EPSS
99.88%
SQL Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8.8
EPSS
99.94%
SQL Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

1 / 2
Source: NVD
First published (updated )
Severity
8.8
EPSS
0.79%
Malicious File Upload
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

First published (updated )
Severity
8.8
EPSS
0.79%
Malicious File Upload
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

First published (updated )
Severity
8.8
EPSS
1.44%
Path Traversal
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

First published (updated )
Severity
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.

First published (updated )
Severity
8.8
EPSS
0.35%
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

First published (updated )
Severity
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

1 / 2
Source: MITRE
First published (updated )
Severity
8.4
EPSS
0.02%
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

First published (updated )
Severity
8.4
EPSS
0.02%
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

First published (updated )
Severity
8.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

First published (updated )
Severity
8
EPSS
8.48%
SQL Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8
EPSS
8.48%
SQL Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8
EPSS
8.23%
SQL Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8
EPSS
8.48%
SQL Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

First published (updated )
Severity
8
Path Traversal
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

First published (updated )
Severity
7.8
Malicious File Upload
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203