vulnerability

Ivanti EPM: CVE-2024-8191: SQL Injection

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 10, 2024
Added
Sep 20, 2024
Modified
Dec 31, 2024

Description

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

Solutions

ivanti-epm-cve-2024-8191-epm-2022ivanti-epm-cve-2024-8191-epm-2024
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.