CVE-2025-62391: SQL Injection
Published Oct 13, 2025
·Updated
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
6 affected components
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Event History
Oct 13, 2025
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62391?
CVE-2025-62391 has a high severity rating due to its potential for unauthorized data access via SQL injection.
2
How do I fix CVE-2025-62391?
To fix CVE-2025-62391, update your Ivanti Endpoint Manager to the latest security release that addresses the SQL injection vulnerability.
3
Who is affected by CVE-2025-62391?
CVE-2025-62391 affects users of Ivanti Endpoint Manager versions prior to 2024 and its subsequent security updates.
4
What are the implications of CVE-2025-62391?
The implications of CVE-2025-62391 include potential unauthorized access to sensitive data stored in the database.
5
Is CVE-2025-62391 a remote vulnerability?
Yes, CVE-2025-62391 is a remote vulnerability that can be exploited by an authenticated attacker.