SQL Injection Vulnerability in EPMM Web Component
CVE-2023-46806

Currently unrated

Key Information:

Vendor
Ivanti
Status
Vendor
CVE Published:
22 May 2024

Summary

An SQL Injection vulnerability exists in a web component of the Ivanti Enterprise Policy Management Mobile (EPMM) product. This vulnerability allows an authenticated user with sufficient privileges to access or modify sensitive data stored in the underlying database. The impact of this vulnerability underscores the importance of enforcing strict access controls and the need for regular updates to mitigate security risks associated with outdated software versions.

Affected Version(s)

EPMM 12.1.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.