ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Researcher Uncovers Critical Flaws in Multiple Versions of Ivanti Endpoint Manager

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10811
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated att

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

NVD description · AI analysis pending
7.54% PoC
  • ivanti endpoint manager
CVE-2024-13159
+2 in the same advisory: …13160 …13161
Unauthenticated Absolute Path Traversal Info Leak in Ivanti Endpoint Manager (EPM)

CVE-2024-13159 is an absolute path traversal vulnerability (CWE-36) in Ivanti Endpoint Manager (EPM) that allows a remote, unauthenticated attacker to leak sensitive information from the server. It is triggered when the EPM server processes attacker-supplied requests containing absolute file-system paths without properly constraining them, letting the attacker retrieve files outside the intended directory. A successful attack discloses arbitrary file contents, which could include configuration or credential material useful for further compromise; the available data describes information disclosure only, not code execution. Any organization running an Ivanti EPM management server, particularly one reachable by untrusted networks, is affected, though the source data does not specify affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating confirmed in-the-wild exploitation, and EPSS assigns it a 100% probability of exploitation within 30 days; no public proof-of-concept is known.

Do: Apply the fixed updates identified in Ivanti's security advisory (specific patched versions are not included in the available data), and follow CISA KEV required action: apply vendor mitigations, comply with BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Until patched, restrict network access to the EPM management server to trusted networks and review HTTP/server logs for requests referencing absolute file paths that could indicate exploitation.

7.5100% KEV PoC
  • Ivanti Endpoint Manager (EPM)
largeon the order of tens of thousands of EPM management-server deployments (unknown share remotely exploitable)
CVE-2025-0066
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

NVD description · AI analysis pending
8.8<1%
  • sap sap basis
CVE-2025-0070
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability.

NVD description · AI analysis pending
9.9<1%
Full article481 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 16, 2025Vulnerability / Endpoint Security

Ivanti has rolled out security updates to address several security flaws impacting Avalanche, Application Control Engine, and Endpoint Manager (EPM), including four critical bugs that could lead to information disclosure.

All the four critical security flaws, rated 9.8 out of 10.0 on the CVSS scale, are rooted in EPM, and concern instances of absolute path traversal that allow a remote unauthenticated attacker to leak sensitive information. The flaws are listed below -

  • CVE-2024-10811
  • CVE-2024-13161
  • CVE-2024-13160, and
  • CVE-2024-13159

The shortcomings affect EPM versions 2024 November security update and prior, and 2022 SU6 November security update and prior. They have been addressed in EPM 2024 January-2025 Security Update and EPM 2022 SU6 January-2025 Security Update.

Horizon3.ai security researcher Zach Hanley has been credited with discovering and reporting all four vulnerabilities in question.

Also patched by Ivanti are multiple high-severity bugs in Avalanche versions prior to 6.4.7 and Application Control Engine before version 10.14.4.0 that could permit an attacker to bypass authentication, leak sensitive information, and get around the application blocking functionality.

The company said it has no evidence that any of the flaws are being exploited in the wild, and that it has intensified its internal scanning and testing procedures to promptly flag and address security issues.

The development comes as SAP released fixes to resolve two critical vulnerabilities in its NetWeaver ABAP Server and ABAP Platform (CVE-2025-0070 and CVE-2025-0066, CVSS scores: 9.9) that allows an authenticated attacker to exploit improper authentication checks in order to escalate privileges and access restricted information due to weak access controls.

"SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape," the company said in its January 2025 bulletin.

Horizon3.ai Releases Technical Details

A little over a month after patches were shipped for the aforementioned flaws, San Francisco-headquartered Horizon3.ai has released additional technical specifics, describing them as "credential coercion" bugs that could allow an unauthenticated attacker to compromise the servers.

The weaknesses discovered could permit an attacker to "coerce the Ivanti EPM machine account credential to be used in relay attacks, potentially allowing for server compromise," Hanley said, adding they reside in a DLL named "WSVulnerabilityCore.dll" that exposes various APIs related to vulnerability management for endpoints management by the EPM server.

  • CVE-2024-13159 - Credential Coercion Vulnerability in GetHashForWildcardRecursive
  • CVE-2024-13160 - Credential Coercion Vulnerability in GetHashForWildcard
  • CVE-2024-13161 - Credential Coercion Vulnerability in GetHashForSingleFile
  • CVE-2024-10811 - Credential Coercion Vulnerability in GetHashForFile

A proof-of-concept (PoC) exploit has also been publicly made available by the company, making it imperative that users move quickly to apply the patches, if not already.

(The story was updated after publication on February 20, 2025, to include information about the release of a PoC.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/01/researcher-uncovers-critical-flaws-in.html