High severity8.2NVD Advisory· Published Sep 12, 2024· Updated Jun 17, 2026
CVE-2024-37397
CVE-2024-37397
Description
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
Affected products
9cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <2022
- cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.