Security
Loading…

CVE-2025-4428

UNKNOWNKnown Exploited
Description

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.

Timeline
Published:May 19th, 2025 12:00 AM
Last modified:May 19th, 2025 12:00 AM
Added to KEV:May 19th, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Ivanti

Products

Endpoint Manager Mobile (EPMM)
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute