CVE-2024-32847
CVSS 3.0 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-32847 is a new SQL injection vulnerability affecting Ivanti Endpoint Manager before the November 2024 Security Update or November 2022 SU6 Security Update. This issue allows a remote, authenticated attacker with administrative privileges to execute arbitrary code, posing a significant threat to affected systems. SQL injection vulnerabilities enable attackers to insert malicious SQL statements into an application's execution flow, potentially leading to unauthorized data access, modification, or complete compromise of the system. Ivanti Endpoint Manager users are advised to apply the available security updates as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Endpoint Manager