CVE-2025-11623: SQL Injection
Published Oct 13, 2025
·Updated
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
6 affected components
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Event History
Oct 13, 2025
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11623?
CVE-2025-11623 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2025-11623?
To fix CVE-2025-11623, update Ivanti Endpoint Manager to the latest patched version.
3
Who is affected by CVE-2025-11623?
CVE-2025-11623 affects all versions of Ivanti Endpoint Manager up to and including version 2024.
4
What type of vulnerability is CVE-2025-11623?
CVE-2025-11623 is an SQL injection vulnerability that allows unauthorized database access.
5
What are the consequences of CVE-2025-11623?
Exploitation of CVE-2025-11623 can lead to unauthorized access to arbitrary data within the database.