SQL Injection Vulnerability in Ivanti Endpoint Manager
CVE-2025-62389

6.5MEDIUM

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
13 October 2025

What is CVE-2025-62389?

A security vulnerability exists within Ivanti Endpoint Manager that exposes the application to SQL injection attacks. This flaw allows remote authenticated attackers to manipulate database queries, potentially enabling them to read arbitrary data from the underlying database. It is crucial for users of Ivanti Endpoint Manager to apply recommended security measures and updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Endpoint Manager 2024 SU3 SR1

Endpoint Manager 2024 SU3 SR1

Endpoint Manager 2022 SU8 SR2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62389 : SQL Injection Vulnerability in Ivanti Endpoint Manager