Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-37397

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.048
EPSS Ranking 89.2%
CVSS Severity
CVSS v3 Score 8.2
Products affected by CVE-2024-37397


Contact Us

Shodan ® - All rights reserved