An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
| Software | From | Fixed in |
|---|---|---|
| ivanti / endpoint_manager_mobile | - | 11.12.0.5 |
| ivanti / endpoint_manager_mobile | 12.3.0.0 | 12.3.0.2 |
| ivanti / endpoint_manager_mobile | 12.4.0.0 | 12.4.0.2 |
| ivanti / endpoint_manager_mobile | 12.5.0.0 | 12.5.0.0.x |