Known vulnerabilities in Endpoint Manager - page 3
Vendor:
Ivanti
Software:
Endpoint Manager
Software CPE:
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*
Website:
https://www.ivanti.com/
Total vulnerabilities:
102
Public exploits:
4
Known exploited (KEV):
6
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2024 SU7
2024 SU6
2024 SU5
2024 SU4 SR1
2024 SU4
2022 SU8 Security Update 2
2024 SU3 Security Update 1
2024 SU3
2022 SU8 Security Update 1
2024 SU2
2022 SU8
2024 SU1
2022 SU7
2022 SU6 January-2025 Update
2024 January-2025 Update
2022 SU6 November Update
2024 November Update
2024 September Update
2024 July Update
2022 SU6
2024
2022 SU2
2022 SU1
2022
4.6
2022 SU5
2022 SU4
2022 SU3
Vulnerabilities (102)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU102847 - Use of Uninitialized Resource CVE-2024-13164 |
CWE-908 | Low | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102846 - Type confusion CVE-2024-13169 |
CWE-843 | Low | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102841 - Out-of-bounds write CVE-2024-13170 |
CWE-787 | Medium | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102843 - Out-of-bounds write CVE-2024-13167 |
CWE-787 | Medium | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102844 - Out-of-bounds write CVE-2024-13166 |
CWE-787 | Medium | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102845 - Out-of-bounds write CVE-2024-13165 |
CWE-787 | Medium | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102840 - Unrestricted Upload of File with Dangerous Type CVE-2024-13171 |
CWE-434 | Medium | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102839 - Improper Verification of Cryptographic Signature CVE-2024-13172 |
CWE-347 | Medium | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102838 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-13158 |
CWE-22 | Low | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102834 - Absolute Path Traversal CVE-2024-10811 |
CWE-36 | High | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102835 - Absolute Path Traversal CVE-2024-13161 |
CWE-36 | High | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102836 - Absolute Path Traversal CVE-2024-13160 |
CWE-36 | High | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU102837 - Absolute Path Traversal CVE-2024-13159 |
CWE-36 | High | 2022 SU6 January-2025 Update, 2024 January-2025 Update | 15.01.2025 |
SB2025011595 |
||
| #VU101967 - Incorrect Default Permissions CVE-2024-10256 |
CWE-276 | Low | 2022 SU6, 2022 SU6 November Update | 27.12.2024 |
SB2024122759 SB2024122760 SB2024122761 and 3 more |
||
| #VU100548 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-34782 |
CWE-89 | Low | 2022 SU6 November Update, 2024 November Update | 15.11.2024 |
SB20241115102 |
||
| #VU100549 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-34784 |
CWE-89 | Low | 2022 SU6 November Update, 2024 November Update | 15.11.2024 |
SB20241115102 |
||
| #VU100550 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-50326 |
CWE-89 | Low | 2022 SU6 November Update, 2024 November Update | 15.11.2024 |
SB20241115102 |
||
| #VU100551 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-50327 |
CWE-89 | Low | 2022 SU6 November Update, 2024 November Update | 15.11.2024 |
SB20241115102 |
||
| #VU100552 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-50328 |
CWE-89 | Low | 2022 SU6 November Update, 2024 November Update | 15.11.2024 |
SB20241115102 |
||
| #VU100539 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-34787 |
CWE-22 | Medium | 2022 SU6 November Update, 2024 November Update | 15.11.2024 |
SB20241115102 |
Showing elements 41 - 60 out of 102