CVE-2025-62384: SQL Injection
Published Oct 13, 2025
·Updated
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
6 affected components
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Event History
Oct 13, 2025
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62384?
CVE-2025-62384 is rated as critical due to its potential for remote authenticated attackers to read arbitrary data from the database.
2
How do I fix CVE-2025-62384?
To fix CVE-2025-62384, upgrade to Ivanti Endpoint Manager version 2024 or later, including all relevant security updates.
3
Who is affected by CVE-2025-62384?
CVE-2025-62384 affects all versions of Ivanti Endpoint Manager up to and including 2024 and its subsequent updates.
4
What type of vulnerability is CVE-2025-62384?
CVE-2025-62384 is an SQL injection vulnerability allowing unauthorized database access.
5
Can CVE-2025-62384 be exploited remotely?
Yes, CVE-2025-62384 can be exploited remotely by authenticated attackers.