CVE Vulnerabilities

CVE-2024-37397

Improper Restriction of XML External Entity Reference

Published: Sep 12, 2024 | Modified: Jul 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Endpoint_manager Ivanti * 2022 (excluding)
Endpoint_manager Ivanti 2022 (including) 2022 (including)
Endpoint_manager Ivanti 2022-su1 (including) 2022-su1 (including)
Endpoint_manager Ivanti 2022-su2 (including) 2022-su2 (including)
Endpoint_manager Ivanti 2022-su3 (including) 2022-su3 (including)
Endpoint_manager Ivanti 2022-su4 (including) 2022-su4 (including)
Endpoint_manager Ivanti 2022-su5 (including) 2022-su5 (including)

Potential Mitigations

References