Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
| Software | From | Fixed in |
|---|---|---|
| ivanti / endpoint_manager | - | 2022 |
| ivanti / endpoint_manager | 2022 | 2022.x |
| ivanti / endpoint_manager | 2022-su1 | 2022-su1.x |
| ivanti / endpoint_manager | 2022-su2 | 2022-su2.x |
| ivanti / endpoint_manager | 2022-su3 | 2022-su3.x |
| ivanti / endpoint_manager | 2022-su4 | 2022-su4.x |
| ivanti / endpoint_manager | 2022-su5 | 2022-su5.x |
| ivanti / endpoint_manager | 2022-su6 | 2022-su6.x |
| ivanti / endpoint_manager | 2022-su7 | 2022-su7.x |
| ivanti / endpoint_manager | 2022-su8 | 2022-su8.x |
| ivanti / endpoint_manager | 2022-su8_security_release_1 | 2022-su8_security_release_1.x |
| ivanti / endpoint_manager | 2024 | 2024.x |
| ivanti / endpoint_manager | 2024-su1 | 2024-su1.x |
| ivanti / endpoint_manager | 2024-su2 | 2024-su2.x |