CVE-2024-34783
An unspecified SQL injection in Ivanti EPM before 2022 SU6,
Description
Description
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVSS Scores
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE ID | Description |
---|---|
CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
Meta Information
Date published:
2024-09-12
Date last modified:
2024-09-12
Date generated:
2025-01-15
NVD report: