Skip to main content
Vulnerability Database/CVE-2025-62383

CVE-2025-62383: Ivanti Endpoint Manager SQL Injection Flaw

CVE-2025-62383 is a SQL injection vulnerability in Ivanti Endpoint Manager that allows authenticated attackers to read sensitive database information. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2025-62383 Overview

CVE-2025-62383 is a SQL injection vulnerability [CWE-89] in Ivanti Endpoint Manager (EPM) versions prior to 2024 SU5. A remote authenticated attacker can inject SQL statements through a vulnerable input parameter and read arbitrary data from the underlying database. The flaw affects confidentiality of stored records without directly modifying data or disrupting availability. Ivanti disclosed the issue in its October 2025 security advisory and released a fix in the 2024 SU5 update.

Critical Impact

Authenticated attackers can extract sensitive database contents from Ivanti Endpoint Manager, including managed device inventory, credentials metadata, and configuration data.

Affected Products

  • Ivanti Endpoint Manager 2024 (base release)
  • Ivanti Endpoint Manager 2024 SU1, SU2, SU3, and SU3 Security Release 1
  • Ivanti Endpoint Manager versions prior to 2024 SU5

Discovery Timeline

  • 2025-10-13 - CVE-2025-62383 published to the National Vulnerability Database
  • 2025-10-13 - Ivanti releases the EPM October 2025 Security Advisory
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-62383

Vulnerability Analysis

The vulnerability is a classic SQL injection weakness in Ivanti Endpoint Manager. User-supplied input reaches a database query without proper parameterization or sanitization. An authenticated attacker on the network can submit crafted input that alters the intended SQL statement.

Exploitation requires valid credentials but no user interaction. The attack targets confidentiality only, allowing arbitrary read access to database contents. Integrity and availability are not directly affected by this specific flaw.

Endpoint Manager stores sensitive operational data about managed endpoints. Successful exploitation exposes device inventories, software configurations, agent metadata, and potentially credential-related records used for endpoint administration.

Root Cause

The root cause is improper neutralization of special elements used in an SQL command [CWE-89]. A backend query concatenates or interpolates attacker-controlled input into a SQL statement instead of using prepared statements with bound parameters. Ivanti has not published the specific vulnerable component in the public advisory.

Attack Vector

The attack vector is network-based and requires low-privilege authentication to the Ivanti Endpoint Manager console or its exposed services. An attacker with a valid EPM account crafts malicious input that is passed to a database query. The injected SQL clauses enable data extraction techniques such as UNION-based reads or boolean/time-based blind inference. See the Ivanti Security Advisory for vendor-provided technical context.

Detection Methods for CVE-2025-62383

Indicators of Compromise

  • Unusual SQL syntax fragments such as UNION SELECT, OR 1=1, WAITFOR DELAY, or comment sequences (--, /*) in EPM web request logs and IIS logs.
  • Unexpected long-running or high-cost queries originating from the EPM application account against the EPM database.
  • Authenticated EPM sessions issuing anomalous request patterns to administrative or reporting endpoints.

Detection Strategies

  • Enable SQL Server auditing on the EPM database to capture query text executed by the EPM service account and flag statements containing injection primitives.
  • Deploy a web application firewall in front of the EPM console with SQL injection signatures tuned to Ivanti EPM URL patterns.
  • Correlate authenticated EPM logins with subsequent database read volume spikes to identify credentialed abuse.

Monitoring Recommendations

  • Forward EPM application, IIS, and Microsoft SQL Server audit logs to a centralized analytics platform for retention and correlation.
  • Alert on failed and successful EPM logins from atypical source addresses or service accounts outside normal administrative jump hosts.
  • Baseline EPM query patterns and alert on deviations that indicate reconnaissance or bulk data reads.

How to Mitigate CVE-2025-62383

Immediate Actions Required

  • Upgrade all Ivanti Endpoint Manager installations to version 2024 SU5 or later as directed by the vendor advisory.
  • Restrict EPM console access to trusted administrative networks and VPN segments only.
  • Rotate credentials for any EPM accounts suspected of exposure and review recent authenticated session activity.
  • Review database audit logs for evidence of injection attempts dating back to before patch deployment.

Patch Information

Ivanti addressed CVE-2025-62383 in Ivanti Endpoint Manager 2024 SU5. Full remediation details, including download locations and update procedures, are available in the Ivanti Security Advisory - EPM October 2025. Apply the update in a maintenance window and validate agent-to-server communications after the upgrade.

Workarounds

  • No official vendor workaround is published; patching to 2024 SU5 is the required remediation.
  • Enforce least privilege on EPM user accounts and remove unnecessary administrative access to reduce the pool of accounts capable of authenticating.
  • Place the EPM management interface behind network segmentation and require multi-factor authentication for all administrative logins.
bash
# Example: verify installed Ivanti EPM version on the core server
reg query "HKLM\SOFTWARE\LANDesk\ManagementSuite\Setup" /v Version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.