CVE-2025-62392: SQL Injection
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62392?
CVE-2025-62392 is classified with a high severity due to its potential for data exposure via SQL injection.
How do I fix CVE-2025-62392?
To fix CVE-2025-62392, you should apply the latest security updates provided by Ivanti for Endpoint Manager.
Who is affected by CVE-2025-62392?
CVE-2025-62392 affects users of Ivanti Endpoint Manager versions prior to 2024 and specific updates within 2024.
What type of attack does CVE-2025-62392 allow?
CVE-2025-62392 allows a remote authenticated attacker to perform SQL injection attacks to read arbitrary data from the database.
What should I do if I suspect exploitation of CVE-2025-62392?
If you suspect exploitation of CVE-2025-62392, you should immediately review your logs and consider applying security updates while temporarily limiting access.