CVE-2024-37397 is an External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti Endpoint Manager (EPM). Affected versions include Ivanti EPM prior to 2022 SU6 and Ivanti EPM 2024 systems missing the September 2024 update. The flaw arises from unsafe processing of XML input that permits external entity resolution, allowing attacker-controlled XML to cause the service to access unintended resources and disclose sensitive information. The vulnerability is remotely exploitable without authentication and specifically enables exposure of API secrets.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ivanti Endpoint Manager XXE vulnerability that can be exploited to gain unauthorized access to sensitive data from the API.
An XXE vulnerability in the provisioning web service of Ivanti EPM that allows a remote unauthenticated attacker to leak API secrets.
An XXE vulnerability in the Ivanti EPM provisioning web service that allows remote unauthenticated disclosure of API secrets.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.