CVE-2023-39336 - CERT CVE
ID CVE-2023-39336
Sažetak An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.
Reference
CVSS
Base: 9.6
Impact: 6.0
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Zadnje važnije ažuriranje 03-06-2025 - 15:15
Objavljeno 09-01-2024 - 02:15