High severity7.2NVD Advisory· Published Sep 12, 2024· Updated Jun 17, 2026
CVE-2024-32845
CVE-2024-32845
Description
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected products
10cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <2022
- cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.