CVE-2024-32847

CVSS 3.0 Score 7.2 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 89

Summary

CVE-2024-32847 is a new SQL injection vulnerability affecting Ivanti Endpoint Manager before the November 2024 Security Update or November 2022 SU6 Security Update. This issue allows a remote, authenticated attacker with administrative privileges to execute arbitrary code, posing a significant threat to affected systems. SQL injection vulnerabilities enable attackers to insert malicious SQL statements into an application's execution flow, potentially leading to unauthorized data access, modification, or complete compromise of the system. Ivanti Endpoint Manager users are advised to apply the available security updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share