VDB

GCVE-110-NCSC-2024-441

GCVE-110-NCSC-2024-441
Advisory PublishedCVSS 7.8/10
Vulnetix · Advisory published November 13, 2024
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - SQL Injection - Omzeilen van beveiligingsmaatregel - Uitvoer van willekeurige code op de server

Weaknesses (CWE)

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Risk Scores

CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
ivantiepm
ivantiendpoint_manager

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,299 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›