NA - CVE-2024-32840 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-32842 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-32843 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-32845 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-32846 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-32848 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-34779 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-34783 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-34785 - An unspecified SQL injection in Ivanti EPM...
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
NA - CVE-2024-37397 - An External XML Entity (XXE) vulnerability in...
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.