CVE-2025-22461: SQL Injection
Published Apr 8, 2025
·Updated
SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.
Affected Software
10 affected components
Ivanti Endpoint Manager<2024 SU1, <2022 SU7
Ivanti Endpoint Manager<2022
Ivanti Endpoint Manager=2022
Ivanti Endpoint Manager=2022-su1
Ivanti Endpoint Manager=2022-su2
Ivanti Endpoint Manager=2022-su3
Ivanti Endpoint Manager=2022-su4
Ivanti Endpoint Manager=2022-su5
Ivanti Endpoint Manager=2022-su6
Ivanti Endpoint Manager=2024
Event History
Apr 8, 2025
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability severity of CVE-2025-22461?
CVE-2025-22461 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How can I mitigate CVE-2025-22461?
To mitigate CVE-2025-22461, update Ivanti Endpoint Manager to version 2024 SU1 or later, or 2022 SU7 or later.
3
Who is affected by CVE-2025-22461?
CVE-2025-22461 affects users of Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7.
4
What type of attack does CVE-2025-22461 enable?
CVE-2025-22461 enables remote authenticated attackers with admin privileges to execute arbitrary code.
5
What products are impacted by CVE-2025-22461?
CVE-2025-22461 impacts Ivanti Endpoint Manager, specifically versions before 2024 SU1 and 2022 SU7.