An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
Metrics
Affected Vendors & Products
References
History
Wed, 21 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 12 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ivanti
Ivanti endpoint Manager Mobile |
|
Weaknesses | CWE-502 | |
CPEs | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ivanti
Ivanti endpoint Manager Mobile |
|
Metrics |
cvssV3_1
|
Wed, 07 Aug 2024 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance. | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2024-08-07T03:54:46.888Z
Updated: 2024-08-21T17:22:15.126Z
Reserved: 2024-05-21T01:04:07.207Z
Link: CVE-2024-36131
Vulnrichment
Updated: 2024-08-07T15:24:04.479Z
NVD
Status : Modified
Published: 2024-08-07T04:17:18.207
Modified: 2024-08-21T18:35:05.670
Link: CVE-2024-36131
Redhat
No data.