Back

MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database

Published Oct 13, 2025

Description

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ivanti
Published Oct 13, 2025
Updated Feb 10, 2026
Reserved Oct 10, 2025
CISA Vulnrichment
Updated Nov 24, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ivanti
Published Oct 13, 2025
Updated Feb 10, 2026
Exploited since n/a
EUVD-2025-34104