An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
| Software | From | Fixed in |
|---|---|---|
| ivanti / endpoint_manager | 2022-su1 | 2022-su1.x |
| ivanti / endpoint_manager | - | 2022 |
| ivanti / endpoint_manager | 2022 | 2022.x |
| ivanti / endpoint_manager | 2022-su2 | 2022-su2.x |
| ivanti / endpoint_manager | 2022-su3 | 2022-su3.x |
| ivanti / endpoint_manager | 2022-su4 | 2022-su4.x |
| ivanti / endpoint_manager | 2022-su5 | 2022-su5.x |