Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2022 SU8
- <= 2024 SU2
A SQL injection vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2022 SU8 and prior, as well as 2024 SU2 and prior. This vulnerability allows remote authenticated attackers with admin privileges to read arbitrary data from the database. The issue arises from improper input validation, enabling attackers to manipulate SQL queries and access sensitive information.
Exploitation of this vulnerability could lead to unauthorized access to database information, potentially including sensitive user data or application records.
Users can upgrade to Ivanti Endpoint Manager 2024 SU3 or 2022 SU8 Security Update 1. The latest versions are available for download through the Ivanti License System.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.