vulnerability

Ivanti EPM: CVE-2024-37397: Improper Restriction of XML External Entity Reference

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:P/A:N)
Published
Sep 10, 2024
Added
Sep 20, 2024
Modified
Dec 31, 2024

Description

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

Solutions

ivanti-epm-cve-2024-37397-epm-2022ivanti-epm-cve-2024-37397-epm-2024
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.