Systems Status

Axios vulnerability in Policy Manager Webreporting

Incident Report for WithSecure services

Investigating

We have identified that WithSecure Policy Manager (PM) includes a version of the Axios library within the web reporting component that is currently flagged as vulnerable.

Based on our assessment, the associated risk is low. As a precautionary measure, we recommend the following:

Reviewing the current firewall and network configuration to ensure that the Policy Manager webreporting interface is not accessible from external networks

Ensuring restricted access to this component significantly reduces any potential exposure.

We are investigating on a fix for the issue.
Posted Apr 14, 2026 - 14:35 UTC
This incident affects: On-Premise solutions (Business Suite).