CVE-2024-13161
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 90.08%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-36
- Published
- 2025-01-14
- Last modified
- 2025-10-21
Affected products
- Ivanti Endpoint Manager
- Ivanti Endpoint Manager
Weakness type
Related vulnerabilities
- CVE-2024-48248 — NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
- CVE-2024-13160 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2024-13159 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2018-20250 — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
- CVE-2023-3765 — Absolute Path Traversal in mlflow/mlflow
- CVE-2025-57790 — Path Traversal Vulnerability
- CVE-2021-21586 — Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated
- CVE-2024-20401 — A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unau