CVE-2025-54397: Medium severity Netwrix Directory Manager vulnerability
Published Aug 7, 2025
·Updated
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.
Affected Software
2 affected components
Netwrix Directory Manager<11.1.25162.02
Netwrix Directory Manager>=11.0.0.0<11.1.25162.02
Event History
Aug 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54397?
CVE-2025-54397 is classified as a critical vulnerability due to its potential to expose sensitive information to authenticated users.
2
How do I fix CVE-2025-54397?
To remediate CVE-2025-54397, upgrade Netwrix Directory Manager to version 11.1.25162.02 or later.
3
What details are exposed by CVE-2025-54397?
CVE-2025-54397 allows the insertion of sensitive information into data sent to authenticated users.
4
Which versions of Netwrix Directory Manager are affected by CVE-2025-54397?
Versions prior to 11.1.25162.02 of Netwrix Directory Manager are affected by CVE-2025-54397.
5
Who should be concerned about CVE-2025-54397?
Organizations using Netwrix Directory Manager versions before 11.1.25162.02 should be concerned about CVE-2025-54397 due to the risk of data exposure.