Back

MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database

Published Oct 13, 2025

Description

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ivanti
Published Oct 13, 2025
Updated Feb 10, 2026
Reserved Oct 10, 2025

CISA Vulnrichment

Updated Oct 14, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ivanti
Published Oct 13, 2025
Updated Feb 10, 2026

GitHub

No data