First published: Tue Apr 08 2025(Updated: )
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.
Credit: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager (EPM) | <2024 SU1<2022 SU7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22465 has been rated as a high severity vulnerability due to its potential for remote code execution via reflected XSS.
To mitigate CVE-2025-22465, upgrade to Ivanti Endpoint Manager version 2024 SU1 or version 2022 SU7 to ensure you are not using a vulnerable version.
CVE-2025-22465 enables remote unauthenticated attackers to execute arbitrary JavaScript in victims' browsers.
Any user of Ivanti Endpoint Manager versions prior to 2024 SU1 or 2022 SU7 can be affected by CVE-2025-22465.
Unlikely user interaction is required for the exploitation of CVE-2025-22465, making it particularly dangerous.