6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
Basic Information
ID
CVE-2025-11623
Source
ivanti
Published
Oct 13, 2025 at 21:09
Affected Product
Vendor
Ivanti
Product
Endpoint Manager
Version
2024 SU3 SR1
Affected Versions
Ivanti Endpoint Manager 2024 SU3 SR1
Ivanti Endpoint Manager 2022 SU8 SR2
Ivanti Endpoint Manager 2022 SU8 SR2