← Back to browse · API

CVE-2024-37397

Severity
HIGH
CVSS
8.2
EPSS
0.59257
Risk score
53.54
CISA KEV
No
PoC
No
Published
2024-09-12
Modified
2024-09-13
First seen
2026-08-07
Aliases
EUVD-2024-36633, GHSA-R268-64HQ-MV45
Products
Ivanti:EPM 2022 SU6 <2022 SU6, Ivanti:EPM 2024 September Security Update <2024 September Security Update
Sources
euvd EUVD-2024-36633

Description

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

References