A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
| Software | From | Fixed in |
|---|---|---|
| ivanti / endpoint_manager_mobile | 11.8.0 | 11.8.1.2 |
| ivanti / endpoint_manager_mobile | 11.9.0 | 11.9.1.2 |
| ivanti / endpoint_manager_mobile | 11.10.0 | 11.10.0.3 |