CVE-2025-62383: SQL Injection
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62383?
CVE-2025-62383 has a high severity rating due to the potential for unauthorized data access via SQL injection.
How do I fix CVE-2025-62383?
To fix CVE-2025-62383, update your Ivanti Endpoint Manager to the latest available version following the vendor's security advisory.
Who is affected by CVE-2025-62383?
CVE-2025-62383 affects all versions of Ivanti Endpoint Manager prior to 2024 and including specific 2024 service updates.
What types of data can an attacker access through CVE-2025-62383?
An attacker exploiting CVE-2025-62383 can potentially read arbitrary data from the database, compromising sensitive information.
What remediation steps should be taken for CVE-2025-62383?
Immediately apply security patches issued by Ivanti and review database access controls to mitigate risks associated with CVE-2025-62383.