0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Vulnerabilities fixed in Ivanti Endpoint Manager (advisories.ncsc.nl)

· 73d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Remote authenticated attacker can leak core server credentials
  • Local authenticated attacker can escalate agent privileges
  • SQL injection in web console allows remote code execution

"Ivanti has fixed multiple vulnerabilities in Ivanti Endpoint Manager. A remote authenticated attacker can leak credentials via a dangerous exposed method in the core server. A local authenticated attacker can escalate privileges due to incorrect permission settings in the agent. A SQL injection in the web console allows a remote authenticated attacker to inject malicious SQL commands, potentially leading to remote code execution. Authentication is required for exploitation."

Discussion Matrix

0 segments

no comments yet.