Ivanti Policy Secure Arbitrary File Read Vulnerability for Authenticated Administrators

Vulnerability

An arbitrary file read vulnerability has been identified in Ivanti Policy Secure versions prior to 22.6R1. This issue allows authenticated administrators to read arbitrary files by sending a maliciously crafted web request.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.

Remediation

Users can upgrade to Ivanti Policy Secure version 22.6R1 to address this vulnerability. For those on the 9.1Rx version, an upgrade to 9.1R18x, tentatively scheduled for late January 2024, is recommended.

Added: Jul 12, 2025, 4:19 AM
Updated: Jul 12, 2025, 4:19 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.8
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.