Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Vendor: Ivanti
Product: Endpoint Manager (EPM)
Added: 2025-03-10
Due Date: 2025-03-31
Description:
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Required Action:
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CWEs: