A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary file read via a maliciously crafted web request.
2025-07-12T04:15:46.107
2025-07-17T13:41:49.867
Analyzed
CVSSv3.0: 4.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | policy_secure | < 22.6 | Yes |
Application | ivanti | policy_secure | 22.6 | Yes |