SQL Injection Vulnerability in Ivanti Endpoint Manager Affecting Remote Authentication
CVE-2025-62392
6.5MEDIUM
What is CVE-2025-62392?
The vulnerability identified in Ivanti Endpoint Manager allows a remote authenticated attacker to exploit SQL injection. This flaw enables attackers to gain unauthorized access and read sensitive data directly from the database, potentially exposing confidential information and compromising system integrity. It’s crucial for users to apply security patches and monitor access to mitigate associated risks.
Affected Version(s)
Endpoint Manager 2024 SU3 SR1
Endpoint Manager 2024 SU3 SR1
Endpoint Manager 2022 SU8 SR2