Executive brief
An absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM) allows a remote, unauthenticated attacker to access and leak sensitive information from the server. The flaw exists in versions prior to the January 2025 security updates for EPM 2024 and EPM 2022 SU6.
Affected products
- Ivanti Endpoint Manager (EPM) Before 2024 January-2025 Security Update; 2022 SU6 before January-2025 Security Update
Timeline
- 2025-01-14: disclosed: NVD Published Date and initial CVE receipt from Ivanti
- 2025-03-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-31: other: CISA KEV remediation due date