Improper Auth in EPMM Web Component <12.1.0.1
CVE-2024-34788 Published on August 7, 2024

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

NVD

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2024-34788 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2024-34788

Want to know whenever a new CVE is published for Ivanti Endpoint Manager Mobile? stack.watch will email you.

 

Affected Versions

Ivanti EPMM: ivanti endpoint_manager_mobile:

Exploit Probability

EPSS
8.16%
Percentile
92.04%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.