CVE-2025-62387
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

CVE-2025-62387 is a SQL injection vulnerability in Ivanti Endpoint Manager (EPM) that allows a remote authenticated attacker to read arbitrary data from the database. It affects all EPM versions prior to 2024 SU5, including 2024, 2024 SU1, 2024 SU2, 2024 SU3, and 2024 SU3 SR1, as well as versions prior to 2024. The vulnerability was published on October 13, 2025, with a patch released as part of Ivanti's October 2025 security advisory. It carries a CVSS v3.1 base score of 6.5 (Medium/High) (Ivanti Advisory, ZDI).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into SQL queries (Feedly). An authenticated attacker with low privileges can send crafted network requests to exploit the injection point, requiring no user interaction and no elevated permissions beyond a valid account. The Zero Day Initiative published an advisory (ZDI-25-939) on October 7, 2025, indicating the vulnerability was reported through their coordinated disclosure program (ZDI).

Impact

Successful exploitation allows a remote authenticated attacker to read arbitrary data from the Ivanti EPM database, resulting in a high confidentiality impact with no effect on integrity or availability. Sensitive organizational data stored within the EPM database — such as endpoint inventory, configuration details, credentials, or policy information — could be exposed to unauthorized parties. Because EPM manages enterprise endpoints, database exposure could facilitate reconnaissance for further lateral movement within the organization (ZDI, Feedly).

Exploitability

As of the time of reporting, there is no confirmed public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The ZDI advisory (ZDI-25-939) was published on October 7, 2025, indicating coordinated disclosure but no weaponized exploit kit has been identified. The EPSS score is approximately 0.054%, reflecting a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify Ivanti EPM instances running versions prior to 2024 SU5 using network scanning or asset inventory tools.
  2. Authentication: Obtain valid low-privilege credentials for the EPM environment (e.g., a standard domain or EPM user account).
  3. Identify injection point: Locate the vulnerable EPM endpoint or parameter that is susceptible to SQL injection, as referenced in ZDI-25-939.
  4. Craft SQL injection payload: Construct a malicious SQL query (e.g., using UNION-based or error-based injection techniques) designed to extract data from the backend database.
  5. Exfiltrate data: Submit the crafted request to the EPM server and retrieve arbitrary database contents, such as endpoint records, credentials, or configuration data (ZDI).

Indicators of compromise

  • Network: Unusual or malformed HTTP requests to Ivanti EPM web endpoints containing SQL metacharacters (e.g., single quotes, UNION SELECT, --, OR 1=1) in query parameters or request bodies.
  • Logs: EPM application or web server logs showing repeated requests with SQL syntax patterns from authenticated user accounts; database error messages logged in EPM server logs indicating malformed queries.
  • Database: Unexpected or anomalous database queries in SQL Server audit logs originating from the EPM application service account, particularly queries involving UNION, SELECT, or accessing tables outside normal EPM operations.
  • Process/Behavior: Authenticated user accounts making an unusually high volume of requests to EPM API endpoints in a short time window, potentially indicating automated SQL injection tooling.

Mitigation and workarounds

Ivanti has released a patch in EPM 2024 SU5, which addresses CVE-2025-62387 along with other vulnerabilities disclosed in the October 2025 security advisory. Organizations should upgrade to EPM 2024 SU5 or later as the primary remediation step (Ivanti Advisory). As interim mitigations, administrators should restrict EPM access to trusted networks, enforce least-privilege principles for EPM user accounts, implement additional database access monitoring, and review EPM audit logs for anomalous query activity (Feedly).

Community reactions

The vulnerability was covered as part of broader reporting on Ivanti's October 2025 patch release, which addressed 13 EPM vulnerabilities in total. Security news outlets including GBHackers, CyberSecurityNews, and CyberPress highlighted the patch batch, noting the inclusion of remote code execution and SQL injection flaws (GBHackers, CyberSecurityNews). The Center for Internet Security (CIS) also issued an advisory noting that multiple vulnerabilities in Ivanti products could allow for remote code execution (CIS Advisory). No significant individual researcher commentary or social media controversy specific to CVE-2025-62387 has been identified.

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8111HIGH8.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-8110HIGH7.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1603HIGH7.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
YesNoFeb 10, 2026
CVE-2026-8109MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1602MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management