Known vulnerabilities in Endpoint Manager 2024 - page 3

Vendor: Ivanti
Version: 2024
Software CPE: cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 55
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Endpoint Manager version 2024 Endpoint Manager 2024 is affected by 55 vulnerabilities: 1 critical, 8 high, 23 medium, 23 low Critical High Medium Low

Vulnerabilities (55)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU97140 - Untrusted Search Path
CVE-2024-8441
CWE-426 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97139 - Deserialization of Untrusted Data
CVE-2024-29847
CWE-502 Critical
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97138 - Improper Access Control
CVE-2024-8322
CWE-284 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97137 - Improper Authentication
CVE-2024-8321
CWE-287 Medium
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97136 - Improper Authentication
CVE-2024-8320
CWE-287 Medium
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97127 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-32840
CWE-89 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97129 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-32843
CWE-89 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97130 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-32845
CWE-89 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97131 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-32846
CWE-89 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97132 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-32848
CWE-89 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97133 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-34779
CWE-89 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97135 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-34785
CWE-89 Low
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97126 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-8191
CWE-89 High
No
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU97125 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-37397
CWE-611 High
Public exploit available
No
2022 SU6, 2024 September Update 11.09.2024 SB2024091108
#VU94520 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-37381
CWE-89 Low
No
No
- 18.07.2024 SB2024071824


Showing elements 41 - 60 out of 55