CVE-2025-62385: SQL Injection
Published Oct 13, 2025
·Updated
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
6 affected components
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Event History
Oct 13, 2025
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62385?
CVE-2025-62385 has been classified with a high severity due to its potential for unauthorized data access.
2
How do I fix CVE-2025-62385?
To fix CVE-2025-62385, you should upgrade Ivanti Endpoint Manager to the latest released version beyond 2024.
3
Who is affected by CVE-2025-62385?
Any organization using Ivanti Endpoint Manager versions up to 2024, including security updates SU1, SU2, and SU3, is affected by CVE-2025-62385.
4
What type of attack is CVE-2025-62385 related to?
CVE-2025-62385 is related to SQL injection attacks that can lead to unauthorized reading of database content.
5
What data can an attacker access through CVE-2025-62385?
An attacker exploiting CVE-2025-62385 can potentially read arbitrary data from the Ivanti Endpoint Manager database.