VYPR
Unrated severityCISA KEVNVD Advisory· Published Jan 14, 2025· Updated Oct 21, 2025

CVE-2024-13159

CVE-2024-13159

Description

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

Affected products

2
  • Ivanti/EPMllm-fuzzy
    Range: before 2024 January-2025 Security Update and before 2022 SU6 January-2025 Security Update
  • Range: 2024 January-2025 Security Update

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.