Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
High
CVE-2023-35078
Disclosure Date: July 25, 2023 (last updated January 04, 2025)
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
8
Attacker Value
High
CVE-2023-35082
Disclosure Date: August 15, 2023 (last updated October 08, 2023)
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
3
Attacker Value
Low
CVE-2024-22026
Disclosure Date: May 22, 2024 (last updated May 24, 2024)
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.
2
Attacker Value
Unknown
CVE-2023-35081
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
1
Attacker Value
Unknown
CVE-2024-7612
Disclosure Date: October 08, 2024 (last updated December 19, 2024)
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
0
Attacker Value
Unknown
CVE-2024-36132
Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.
0
Attacker Value
Unknown
CVE-2024-36131
Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
0
Attacker Value
Unknown
CVE-2024-36130
Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
0
Attacker Value
Unknown
CVE-2024-34788
Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information
0
Attacker Value
Unknown
CVE-2023-6105
Disclosure Date: November 15, 2023 (last updated February 14, 2025)
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
0