This advisory is for organizations that use Ivanti Endpoint Manager (and additional Ivanti products noted below). If your organization does not use this platform, this notification may be discarded.
Summary
Last week, Ivanti issued patches to address multiple critical security flaws found in the Ivanti Endpoint Manager (EPM). Ivanti has not received any current reports of this vulnerability being exploited.
CVE-2024-29822
|
9.6
|
An unspecified SQL injection vulnerability in Core server of Ivanti EPM 2022 SU5 (five) and prior, allows an unauthenticated attacker within the same network to execute arbitrary code
|
CVE-2024-29823
|
9.6
|
CVE-2024-29824
|
9.6
|
CVE-2024-29825
|
9.6
|
CVE-2024-29826
|
9.6
|
CVE-2024-29827
|
9.6
|
Additional vulnerabilities have been addressed for the following Ivanti products:
Affected Platforms
A Security Hot Patch is available for EPM 2022 SU5 and can be applied as follows:
Note: This Hot Patch is only supported for 2022 SU5. These CVEs will be resolved future releases of EPM.
Additional Resources
https://forums.ivanti.com/s/article/KB-Security-Advisory-EPM-May-2024?language=en_US
https://forums.ivanti.com/s/article/Security-Advisory-May-2024?language=en_US