Reference material — not professional advice. Test in staging, back up first, verify against your specific version. Use your own judgment for your environment.
● Critical · CVSS 9.8 ⚠ ACTIVELY EXPLOITED — CISA KEV

How to Fix CVE-2024-13160: Ivanti EPM Path Traversal (Sibling)

*By Sai Kiran Pandrala*

⚡ At a glance
SeverityCVSS 9.8, Critical
Actively exploited?Yes, listed in CISA KEV
AffectedIvanti EPM 2024 and EPM 2022, same as the bundle
Fixed inEPM 2024 January 2025 Security Update; EPM 2022 SU6 January 2025 Security Update
Type (CWE)Absolute Path Traversal

CVE-2024-13160 is one of three matched Ivanti EPM path-traversal vulnerabilities. Full remediation procedure is at How to Fix CVE-2024-13161, applying the January 2025 Security Update fixes all three CVEs in one operation.

What's different about CVE-2024-13160?

It is a distinct vulnerable code path in EPM with the same flaw class as CVE-2024-13161 and CVE-2024-13159. Different endpoint, same root cause (insufficient path sanitization), same impact (file read/write outside intended directory), same fix.

How to fix CVE-2024-13160

Apply the Ivanti EPM January 2025 Security Update. The full procedure is at How to Fix CVE-2024-13161. One upgrade closes all three sibling CVEs.

Frequently asked questions

Is CVE-2024-13160 actively exploited?

Yes. CVE-2024-13160 is on the CISA Known Exploited Vulnerabilities catalog, so federal civilian agencies are required to patch on the published deadline. Most enterprises treat the same date as the practical floor.

What is the CVSS severity of CVE-2024-13160?

Critical. See the advisory for the full CVSS vector.

Where can I read the official advisory?

See https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022

Does the patch require a reboot?

It depends on the deployment. Service-only updates usually need a service restart; OS-level fixes require a full reboot. Check the vendor release notes for the exact post-upgrade steps.

References


*This guide is one of the bundle siblings. The primary write-up with full procedure is at how-to-fix-cve-2024-13161.*