An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Sep 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 |
Fri, 13 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ivanti endpoint Manager
|
|
Weaknesses | CWE-611 | |
CPEs | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ivanti epm
|
Ivanti endpoint Manager
|
Thu, 12 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ivanti
Ivanti epm |
|
Weaknesses | CWE-200 | |
CPEs | cpe:2.3:a:ivanti:epm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ivanti
Ivanti epm |
|
Metrics |
cvssV3_1
|
Thu, 12 Sep 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets. | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2024-09-12T01:09:56.254Z
Updated: 2024-09-13T15:48:43.529Z
Reserved: 2024-06-08T01:04:07.092Z
Link: CVE-2024-37397
Vulnrichment
Updated: 2024-09-12T14:27:31.393Z
NVD
Status : Awaiting Analysis
Published: 2024-09-12T02:15:03.700
Modified: 2024-09-13T16:35:09.630
Link: CVE-2024-37397
Redhat
No data.