EUVD-2024-51387
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 10 Mar 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2025-0017Kwetsbaarheden verholpen in Ivanti Endpoint Manager
