Known vulnerabilities in Endpoint Manager Mobile (formerly MobileIron Core) - page 2

Vendor: Ivanti
Software CPE: cpe:2.3:a:ivanti:mobileiron_core:*:*:*:*:*:*:*:*
Total vulnerabilities: 34
Public exploits: 9
Known exploited (KEV): 10
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Endpoint Manager Mobile (formerly MobileIron Core) Endpoint Manager Mobile (formerly MobileIron Core) is affected by 34 known vulnerabilities: 5 critical, 10 high, 7 medium, 12 low Critical High Medium Low

Vulnerabilities (34)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU94517 - Deserialization of Untrusted Data
CVE-2024-36131
CWE-502 Medium
No
No
11.12.0.3, 12.0.0.3, 12.1.0.1 18.07.2024 SB2024071823
#VU94516 - Improper Authorization
CVE-2024-36130
CWE-285 Medium
No
No
11.12.0.3, 12.0.0.3, 12.1.0.1 18.07.2024 SB2024071823
#VU89767 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-22026
CWE-78 Low
Available
No
11.12.0.1, 12.0.0.0, 12.1.0.0 23.05.2024 SB2024052308
#VU89766 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-46807
CWE-89 Low
No
No
11.12.0.1, 12.0.0.0, 12.1.0.0 23.05.2024 SB2024052308
#VU89765 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-46806
CWE-89 Low
No
No
11.12.0.1, 12.0.0.0, 12.1.0.0 23.05.2024 SB2024052308
#VU85042 - Improper Authentication
CVE-2023-39335
CWE-287 High
No
No
11.10.0.4, 11.11.0.2, 11.12.0.0 05.01.2024 SB2024010550
#VU78947 - Improper Authentication
CVE-2023-30578
CWE-287 High
No
No
11.8.1.1, 11.9.1.1, 11.10.0.2 04.08.2023 SB2023080417
#VU78929 - Improper Authentication
CVE-2023-35082
CWE-287 High
Available
Exploited
11.3.0.0 03.08.2023 SB2023080345
#VU78757 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-35081
CWE-22 High
No
Exploited
11.8.1.2, 11.9.1.2, 11.10.0.3 29.07.2023 SB2023072907
#VU78625 - Improper Authentication
CVE-2023-35078
CWE-287 Critical
Available
Exploited
11.8.1.1, 11.9.1.1, 11.10.0.2 25.07.2023 SB2023072510
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
- 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU46747 - Improper Authentication
CVE-2020-15506
CWE-287 High
No
No
- 16.09.2020 SB2020070742
#VU46746 - Exposure of sensitive information to an unauthorized actor
CVE-2020-15507
CWE-200 Medium
No
No
- 16.09.2020 SB2020070742
#VU46745 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-15505
CWE-94 High
Available
Exploited
- 07.07.2020 SB2020070742


Showing elements 21 - 40 out of 34