Local Authentication Flaw in Ivanti Workspace Control Exposes SQL Credentials
CVE-2025-22455

8.8HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
10 June 2025

What is CVE-2025-22455?

A hardcoded key vulnerability in Ivanti Workspace Control prior to version 10.19.0.0 enables local authenticated attackers to access and decrypt sensitive SQL credentials. This flaw poses a significant risk as it could potentially lead to unauthorized access to databases, compromising data integrity and confidentiality. Organizations using affected versions are strongly encouraged to upgrade to mitigate the risk.

Affected Version(s)

Workspace Control 10.19.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22455 : Local Authentication Flaw in Ivanti Workspace Control Exposes SQL Credentials