Ivanti Patches Remotely Exploitable Flaws in Endpoint Manager
Ivanti has issued patches for several vulnerabilities found in its Endpoint Manager (EPM) software. According to the vendor, the flaws could allow an attacker to remotely exploit weaknesses that leak credentials used for external SQL database connections, or cause an agent service to crash.
Endpoint Manager is widely used by organisations to manage and secure devices across their networks, making it an attractive target for attackers looking to gain a foothold or disrupt operations. Credential leaks in particular are concerning, as stolen SQL connection details could potentially be used to access sensitive backend systems if not properly secured or rotated.
Australian businesses using Ivanti EPM should apply the available updates as soon as possible. While no active exploitation has been reported, remotely exploitable vulnerabilities are often targeted quickly once details become public, so timely patching reduces the window of opportunity for attackers.