Ivanti Endpoint Manager vulnerable to SQL Injection
CVE-2024-32841
7.2HIGH
What is CVE-2024-32841?
A critical SQL injection flaw allows a remote authenticated attacker with administrative privileges to execute arbitrary code within Ivanti Endpoint Manager, impacting versions before the November 2024 Security Update and the November 2022 SU6. This vulnerability poses a significant risk, enabling unauthorized access and potential control over affected systems, necessitating immediate remediation.
Affected Version(s)
EPM 2024 November Security Update
EPM 2022 SU6 November Security Update