CVE-2025-62386: SQL Injection
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2025-62386?
CVE-2025-62386 is a vulnerability in Ivanti Endpoint Manager that allows a remote authenticated attacker to perform SQL injection and read arbitrary data from the database.
What are the affected versions for CVE-2025-62386?
CVE-2025-62386 affects Ivanti Endpoint Manager versions prior to 2024 and specific 2024 updates including 2024-su1, 2024-su2, and 2024-su3.
How do I fix CVE-2025-62386?
To fix CVE-2025-62386, users must upgrade their Ivanti Endpoint Manager to version 2024 or the latest security update.
What is the risk associated with CVE-2025-62386?
The risk associated with CVE-2025-62386 is high, as it allows attackers to gain unauthorized access to sensitive database information.
Who is vulnerable to CVE-2025-62386?
Any organization using a vulnerable version of Ivanti Endpoint Manager is at risk for CVE-2025-62386.