Vulnerability CVE-2024-29824


Published: 2024-05-31

Description:
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Ivanti EPM RecordGoodApp SQL Injection / Remote Code Execution
Christophe de la...
09.07.2024

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://forums.ivanti.com/s/article/Security-Advisory-May-2024

Copyright 2024, cxsecurity.com

 

Back to Top