An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Link | Tags |
---|---|
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM | vendor advisory |