CVE-2025-15344: Tanium addressed a SQL injection vulnerability in Asset.
Published Jan 28, 2026
·Updated
Tanium addressed a SQL injection vulnerability in Asset.
Affected Software
4 affected components
Tanium Asset
Tanium Asset<1.28.254
Tanium Asset>=1.32<1.32.161
Tanium Asset>=1.33<1.33.250
Event History
Jan 28, 2026
CVE Published
via MITRE·11:46 PM
Data Sourced
via MITRE·11:46 PM
DescriptionSeverityWeakness
Jan 29, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15344?
CVE-2025-15344 has been classified as a high severity vulnerability due to its potential to allow unauthorized access to sensitive data.
2
How do I fix CVE-2025-15344?
To fix CVE-2025-15344, it is recommended to apply the latest security patch provided by Tanium for the Asset product.
3
What impact does CVE-2025-15344 have on Tanium Asset?
CVE-2025-15344 enables attackers to perform SQL injection, which could compromise the integrity and confidentiality of data in Tanium Asset.
4
Who is affected by CVE-2025-15344?
Any organization using Tanium Asset that has not applied the necessary security updates is at risk from CVE-2025-15344.
5
Is there a workaround for CVE-2025-15344 if I can't patch immediately?
While the best practice is to apply the patch, limiting access to the affected components can mitigate the risk of CVE-2025-15344 temporarily.