E25-j7oa1
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2024
Description
This strike targets an SQL injection vulnerability in Ivanti Endpoint Manager. The issue resides in the improper validation of user input within the GetComputerID method of the DPIDatabase.dll component. Exploiting this vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands on the database of the affected server.
CVE
References
https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022?language=en_US