Products
Ivanti EPM
- 2024
Source
support@hackerone.com
Tags
CVE-2024-37381 details
Published : July 29, 2024, 6:15 a.m.
Last Modified : July 29, 2024, 2:12 p.m.
Last Modified : July 29, 2024, 2:12 p.m.
Description
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8.4 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
CVSS Data
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
8.4
Exploitability Score
1.7
Impact Score
6.0
Base Severity
HIGH
Vector String : CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References
URL | Source |
---|---|
https://forums.ivanti.com/s/article/Security-Advisory-EPM-July-2024-for-EPM-2024 | support@hackerone.com |
This website uses the NVD API, but is not approved or certified by it.