Local Authentication Flaw in Ivanti Workspace Control Exposes SQL Credentials
CVE-2025-22455
8.8HIGH
What is CVE-2025-22455?
A hardcoded key vulnerability in Ivanti Workspace Control prior to version 10.19.0.0 enables local authenticated attackers to access and decrypt sensitive SQL credentials. This flaw poses a significant risk as it could potentially lead to unauthorized access to databases, compromising data integrity and confidentiality. Organizations using affected versions are strongly encouraged to upgrade to mitigate the risk.
Affected Version(s)
Workspace Control 10.19.0.0