CVE-2025-48749: Critical severity netwrix directory manager vulnerability
Published May 28, 2025
·Updated
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
Affected Software
2 affected components
Netwrix Directory Manager<=11.0.0.0, >11.1.25134.03
Netwrix Directory Manager>=11.0.0.0<11.1.25134.03
Event History
May 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48749?
CVE-2025-48749 has been classified as a critical vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2025-48749?
To mitigate CVE-2025-48749, update Netwrix Directory Manager to a version later than 11.1.25134.03.
3
What type of information is affected by CVE-2025-48749?
CVE-2025-48749 can lead to the insertion of sensitive information into data that is sent out from the application.
4
Is my version of Netwrix Directory Manager affected by CVE-2025-48749?
Netwrix Directory Manager versions 11.0.0.0 and versions before 11.1.25134.03 are vulnerable to CVE-2025-48749.
5
What are the potential risks associated with CVE-2025-48749?
The risks of CVE-2025-48749 include unauthorized access to sensitive data, which can lead to data breaches and compliance violations.