Show filters
177 Total Results
Displaying 61-70 of 177
Sort by:
Attacker Value
Unknown

CVE-2024-8191

Disclosure Date: September 10, 2024 (last updated September 13, 2024)
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
Attacker Value
Unknown

CVE-2024-36132

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.
Attacker Value
Unknown

CVE-2024-36131

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
Attacker Value
Unknown

CVE-2024-36130

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
Attacker Value
Unknown

CVE-2024-34788

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information
Attacker Value
Unknown

CVE-2024-29846

Disclosure Date: May 31, 2024 (last updated October 04, 2024)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-29830

Disclosure Date: May 31, 2024 (last updated October 04, 2024)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-29829

Disclosure Date: May 31, 2024 (last updated October 04, 2024)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-29828

Disclosure Date: May 31, 2024 (last updated October 04, 2024)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-29827

Disclosure Date: May 31, 2024 (last updated October 04, 2024)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.