CVE-2025-22465: XSS
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22465?
CVE-2025-22465 has been rated as a high severity vulnerability due to its potential for remote code execution via reflected XSS.
How do I fix CVE-2025-22465?
To mitigate CVE-2025-22465, upgrade to Ivanti Endpoint Manager version 2024 SU1 or version 2022 SU7 to ensure you are not using a vulnerable version.
What types of attacks does CVE-2025-22465 enable?
CVE-2025-22465 enables remote unauthenticated attackers to execute arbitrary JavaScript in victims' browsers.
Who can be affected by CVE-2025-22465?
Any user of Ivanti Endpoint Manager versions prior to 2024 SU1 or 2022 SU7 can be affected by CVE-2025-22465.
Is user interaction required for CVE-2025-22465 exploitation?
Unlikely user interaction is required for the exploitation of CVE-2025-22465, making it particularly dangerous.