CVE-2025-62388: SQL Injection
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62388?
CVE-2025-62388 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive database information.
How do I fix CVE-2025-62388?
To fix CVE-2025-62388, upgrade your Ivanti Endpoint Manager to version 2024 or later, ensuring that all security updates are applied.
Who is affected by CVE-2025-62388?
CVE-2025-62388 affects all versions of Ivanti Endpoint Manager prior to 2024, including specific updates SU1, SU2, and SU3.
Can CVE-2025-62388 be exploited remotely?
Yes, CVE-2025-62388 can be exploited remotely by an authenticated attacker, allowing them to read arbitrary data from the database.
What type of vulnerability is CVE-2025-62388?
CVE-2025-62388 is classified as an SQL injection vulnerability, which compromises database integrity and confidentiality.