Ivanti Endpoint Manager SQL Injection in GetComputerID Method

Strike ID:
E25-j7oa1
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2024

Description

This strike targets an SQL injection vulnerability in Ivanti Endpoint Manager. The issue resides in the improper validation of user input within the GetComputerID method of the DPIDatabase.dll component. Exploiting this vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands on the database of the affected server.

CVE

References