Executive brief
An unspecified SQL injection vulnerability in the Core server of Ivanti Endpoint Manager (EPM) allows an unauthenticated attacker on the same network to execute arbitrary code. The vulnerability is confirmed to be exploited in the wild.
Affected products
- Ivanti Endpoint Manager (EPM) 2022 SU5 and prior
Timeline
- 2024-05-31: disclosed: NVD Published Date
- 2024-10-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-10-23: other: CISA KEV remediation due date