Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36633 | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 13 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Fri, 13 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti endpoint Manager
|
|
| Weaknesses | CWE-611 | |
| CPEs | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ivanti epm
|
Ivanti endpoint Manager
|
Thu, 12 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti
Ivanti epm |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:ivanti:epm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ivanti
Ivanti epm |
|
| Metrics |
cvssV3_1
|
Thu, 12 Sep 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-13T15:48:43.529Z
Reserved: 2024-06-08T01:04:07.092Z
Link: CVE-2024-37397
Updated: 2024-09-12T14:27:31.393Z
Status : Analyzed
Published: 2024-09-12T02:15:03.700
Modified: 2025-07-10T21:23:19.787
Link: CVE-2024-37397
No data.
OpenCVE Enrichment
No data.
EUVD