A severe vulnerability has been discovered in Ivanti Endpoint Manager Mobile (EPMM), which allows attackers to execute code on the server without authentication. The issue lies in how the system validates input before verifying whether a user is authorized. This flaw allows the application to be compromised simply by sending a specially crafted web request.
| Product | MobileIron-MDM |
| Date | 2025-05-20 14:04:56 |
| Information |
|
Technical Summary
CVE-2025-4427 and CVE-2025-4428 stem from how Ivanti EPMM handles validation and security checks in Spring MVC. Specifically:
- When a user sends a request to endpoints such as
/api/v2/featureusage, the request parameters are bound to a data object (DeviceFeatureUsageReportQueryRequest). - If the
@Validannotation is used, Spring invokes custom validators likeDeviceFeatureUsageReportQueryRequestValidatorbefore verifying whether the user is authenticated or authorized. - Within this validator, Ivanti uses
buildConstraintViolationWithTemplate()with unfiltered input controlled by the attacker. - Since Hibernate Validator can process EL expressions (e.g.,
${3*333}), these are evaluated immediately in the server context. - Consequently, an attacker can achieve unauthenticated Remote Code Execution (RCE) by injecting malicious EL expressions (Expression Language Injection).
- A similar issue also exists in
ScepSubjectValidator, triggered during SCEP certificate enrollment by an authenticated administrator. - The vulnerability was introduced due to a fundamental flaw in Spring’s validation order: bean validation occurs before Spring Security’s
@PreAuthorizeaccess checks.
Example:
A GET request to:
GET /api/v2/featureusage?format=${3*333} HTTP/2
returns:
Format '999' is invalid. Valid formats are 'json', 'csv'.
confirming that EL expressions are evaluated—even without authentication.
Recommendations
Organizations using Ivanti EPMM should update immediately to one of the patched versions:
- 11.12.0.5
- 12.3.0.2
- 12.4.0.2
- 12.5.0.1
Additionally:
- Verify custom validators to ensure they do not insert untrusted data into error messages.
- Disable EL evaluation in template rendering where not necessary.
- Ensure that authorization checks always occur before any user input processing or validation logic.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
