VYPR
High severity7.8NVD Advisory· Published Dec 5, 2022· Updated Jun 17, 2026

CVE-2022-35259

CVE-2022-35259

Description

XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

Affected products

3
  • cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <=2022.3
    • (no CPE)range: <=2022.3
  • Endpoint Manager/Endpoint Managerdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.