
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62387 is a SQL injection vulnerability in Ivanti Endpoint Manager (EPM) that allows a remote authenticated attacker to read arbitrary data from the database. It affects all EPM versions prior to 2024 SU5, including 2024, 2024 SU1, 2024 SU2, 2024 SU3, and 2024 SU3 SR1, as well as versions prior to 2024. The vulnerability was published on October 13, 2025, with a patch released as part of Ivanti's October 2025 security advisory. It carries a CVSS v3.1 base score of 6.5 (Medium/High) (Ivanti Advisory, ZDI).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into SQL queries (Feedly). An authenticated attacker with low privileges can send crafted network requests to exploit the injection point, requiring no user interaction and no elevated permissions beyond a valid account. The Zero Day Initiative published an advisory (ZDI-25-939) on October 7, 2025, indicating the vulnerability was reported through their coordinated disclosure program (ZDI).
Successful exploitation allows a remote authenticated attacker to read arbitrary data from the Ivanti EPM database, resulting in a high confidentiality impact with no effect on integrity or availability. Sensitive organizational data stored within the EPM database — such as endpoint inventory, configuration details, credentials, or policy information — could be exposed to unauthorized parties. Because EPM manages enterprise endpoints, database exposure could facilitate reconnaissance for further lateral movement within the organization (ZDI, Feedly).
As of the time of reporting, there is no confirmed public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The ZDI advisory (ZDI-25-939) was published on October 7, 2025, indicating coordinated disclosure but no weaponized exploit kit has been identified. The EPSS score is approximately 0.054%, reflecting a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
UNION SELECT, --, OR 1=1) in query parameters or request bodies.UNION, SELECT, or accessing tables outside normal EPM operations.Ivanti has released a patch in EPM 2024 SU5, which addresses CVE-2025-62387 along with other vulnerabilities disclosed in the October 2025 security advisory. Organizations should upgrade to EPM 2024 SU5 or later as the primary remediation step (Ivanti Advisory). As interim mitigations, administrators should restrict EPM access to trusted networks, enforce least-privilege principles for EPM user accounts, implement additional database access monitoring, and review EPM audit logs for anomalous query activity (Feedly).
The vulnerability was covered as part of broader reporting on Ivanti's October 2025 patch release, which addressed 13 EPM vulnerabilities in total. Security news outlets including GBHackers, CyberSecurityNews, and CyberPress highlighted the patch batch, noting the inclusion of remote code execution and SQL injection flaws (GBHackers, CyberSecurityNews). The Center for Internet Security (CIS) also issued an advisory noting that multiple vulnerabilities in Ivanti products could allow for remote code execution (CIS Advisory). No significant individual researcher commentary or social media controversy specific to CVE-2025-62387 has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."