Vulnerabilities > Ivanti

DATE CVE VULNERABILITY TITLE RISK
2024-10-08 CVE-2024-9381 Path Traversal vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.5/4.6
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
network
low complexity
ivanti CWE-22
7.2
2024-09-19 CVE-2024-8963 Path Traversal vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.6
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
network
low complexity
ivanti CWE-22
critical
9.1
2024-09-12 CVE-2024-29847 Deserialization of Untrusted Data vulnerability in Ivanti Endpoint Manager
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
network
low complexity
ivanti CWE-502
critical
9.8
2024-09-12 CVE-2024-32840 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-32842 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-32843 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-32845 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-32846 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-32848 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-34779 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2