CVE-2024-29822
CVE-2024-29822
8.8
HighPublished:
Last updated:
Source:support@hackerone.com
Modified
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Adjacent
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
References
support@hackerone.com
https://forums.ivanti.com/s/article/Security-Advisory-May-2024af854a3a-2127-422b-91ae-364da2661108
https://forums.ivanti.com/s/article/Security-Advisory-May-2024