QID 379224
QID 379224: Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
Ivanti Endpoint Manager is used to find and remediate malware, diagnose problems and identify faulty or nonapproved processes. Ivanti EPM is vulnerable to SQL injection vulnerability which may result in remote code execution.
Affected Versions:
Ivanti EPM 2021 and EPM 2022 prior to SU5
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of Ivanti EPM by fetching the version from registry.
If exploited, an attacker with access to the internal network can leverage an unspecified SQL injection to execute arbitrary SQL queries and retrieve output without the need for authentication. This can then allow the attacker control over machines running the EPM agent. When the core server is configured to use SQL express, this might lead to RCE on the core server.
- Ivanti Security Advisory -
forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336
CVEs related to QID 379224
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ivanti Security Advisory |
|