Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2019-12374

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in Provisioning.Secure.dll.
0
Attacker Value
Unknown

CVE-2019-12375

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.
0
Attacker Value
Unknown

CVE-2019-12373

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.
0
Attacker Value
Unknown

CVE-2019-12376

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.
0
Attacker Value
Unknown

CVE-2019-12377

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.
0