VYPR

Endpoint Manager Mobile

by Ivanti

CVEs (98)

  • CVE-2025-62389MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.02

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62388MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62387MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.02

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62386MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62385MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62384MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62383MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-11623MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2024-34788MedAug 7, 2024
    risk 0.42cvss 6.5epss 0.01

    An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

  • CVE-2023-35083MedOct 18, 2023
    risk 0.42cvss 6.5epss 0.01

    Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.

  • CVE-2023-38344MedSep 21, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The application does not sufficiently restrict user-supplied paths,…

  • CVE-2025-22465MedApr 8, 2025
    risk 0.40cvss 6.1epss 0.01

    Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.

  • CVE-2025-22464MedApr 8, 2025
    risk 0.40cvss 6.1epss 0.00

    An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.

  • CVE-2024-8321MedSep 10, 2024
    risk 0.38cvss 5.8epss 0.02

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.

  • CVE-2024-8320MedSep 10, 2024
    risk 0.35cvss 5.3epss 0.01

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.

  • CVE-2025-10986MedOct 14, 2025
    risk 0.31cvss 4.7epss 0.01

    Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.

  • CVE-2025-22459MedApr 8, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.

  • CVE-2024-8322MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.01

    Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

Page 5 of 5