Home Ivanti CVE-2024-37381
Back to Ivanti

CVE-2024-37381

Ivanti EPM - Core Server

Ivanti CVSS 8 Updated March 16, 2026

Executive Risk Summary

"An authenticated attacker within the same network can execute arbitrary code due to an unspecified SQL Injection vulnerability in the Core server of Ivanti EPM 2024. This vulnerability allows for potential data integrity and confidentiality breaches, as well as system compromise."

Operational Audit Arsenal

Target Type Database Server
Target Asset Core Server
Standard Path Global Configuration

Manual Verification Required

This is a non-Windows asset (Ivanti). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Moderate

Internal Work Notes

SQL Injection vulnerability in Ivanti EPM Core Server allows arbitrary code execution, requiring immediate patching to prevent data breaches and system compromise.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Ivanti Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.