CVE-2025-62386 Details
Description
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
A SQL injection vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 SU3 SR1 and prior, as well as in the 2022 version through SU8 SR2. This vulnerability allows remote authenticated attackers to read arbitrary data from the database. The issue arises from insufficient input validation, which enables attackers to manipulate SQL queries and access sensitive data.
EPM administrators can remove the Reporting database user from their configuration to address this vulnerability, but this will disable reporting functionality. For those running Ivanti EPM 2024 SU3 SR1, the risk is significantly reduced due to important security enhancements. Customers using the 2022 version should upgrade to the latest version of Ivanti EPM 2024.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025 | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2024 2024 - 2024 su1 2024 su2 2024 su3 2024 su3_security_release_1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | CVE Modified | ivanti |
| Oct 15, 2025 | Initial Analysis | [email protected] |
| Oct 13, 2025 | New CVE Received | ivanti |