CVE-2025-48749 Details
Description
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
A vulnerability exists in Netwrix Directory Manager (formerly Imanami GroupID) versions 11.0.0.0 prior to 11.1.25134.03, allowing sensitive information to be inadvertently included in data sent from the application. This issue could enable an authenticated user to access and potentially compromise integrated Identity Stores.
Netwrix has released an update to address this vulnerability. The update is available through the Netwrix Customer Portal. After applying the update, customers are advised to rotate the credentials for all configured Identity Stores.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| netwrix directory manager | >= 11.0.0.0, < 11.1.25134.03 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2025 | Initial Analysis | [email protected] |
| May 28, 2025 | CVE Modified | CISA-ADP |
| May 28, 2025 | New CVE Received | [email protected] |