EPMM Web component insecure deserialization (pre-12.1.0.1) OS cmd exec
CVE-2024-36131 Published on August 7, 2024
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2024-36131 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2024-36131
Want to know whenever a new CVE is published for Ivanti Endpoint Manager Mobile? stack.watch will email you.
Affected Versions
Ivanti EPMM:- Version 12.1.0.1 and below 12.1.0.1 is affected.
- Before 12.1.0.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.