SQL Injection Vulnerability in Ivanti Endpoint Manager Affecting Remote Authentication
CVE-2025-62392

6.5MEDIUM

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
13 October 2025

What is CVE-2025-62392?

The vulnerability identified in Ivanti Endpoint Manager allows a remote authenticated attacker to exploit SQL injection. This flaw enables attackers to gain unauthorized access and read sensitive data directly from the database, potentially exposing confidential information and compromising system integrity. It’s crucial for users to apply security patches and monitor access to mitigate associated risks.

Affected Version(s)

Endpoint Manager 2024 SU3 SR1

Endpoint Manager 2024 SU3 SR1

Endpoint Manager 2022 SU8 SR2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62392 : SQL Injection Vulnerability in Ivanti Endpoint Manager Affecting Remote Authentication