PT-2025-29291 · Ivanti · Ivanti Policy Secure

Published

2025-07-12

·

Updated

2025-07-14

·

CVE-2023-39339

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Ivanti Policy Secure versions prior to 22.6R1
Description: A vulnerability exists where an authenticated administrator can perform an arbitrary file read via a maliciously crafted web request.
Recommendations: Update Ivanti Policy Secure to version 22.6R1 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-39339

Affected Products

Ivanti Policy Secure