Ivanti has disclosed 13 vulnerabilities in its Endpoint Manager (EPM) software, including two high-severity vulnerabilities that could allow remote code execution and privilege escalation . Customers are urged to implement some protective restrictions while fixes are being developed.

The announcement comes amid growing attention on business management tools as attackers increasingly target them for supply chain breaches.
Although no exploit has been reported, the issues highlight the risks of unpatched installations in endpoint security environments.
See also: Oracle patches new vulnerability in E-Business Suite
Ivanti: The most serious vulnerabilities
CVE -2025-9713 is listed as a high severity “path traversal issue” with a CVSS score of 8.8. It allows unauthenticated remote attackers to execute arbitrary code if users interact with malicious files. This vulnerability, based on CWE-22, exploits weak input validation during configuration imports, potentially allowing adversaries to upload and execute malicious payloads on the EPM Core server.
CVE -2025-11622 is a deserialization vulnerability (CVSS 7.8, CWE-502) that allows local authorized users to escalate privileges, gaining unauthorized access to sensitive system resources.
The remaining 11 vulnerabilities are medium severity SQL injection vulnerabilities (each with CVSS 6.5, CWE-89), such as CVE-2025-11623 and CVE-2025-62392 through CVE-2025-62384. These allow remote, authorized attackers to extract arbitrary data from the database, including credentials or configuration details (without requiring user interaction beyond initial authentication).
See also: Axis Communications: Vulnerability exposes Azure Storage Account credentials

Ivanti noted that all issues were responsibly reported by a researcher through Trend Micro 's Zero Day initiative . No proof-of-concept exploits or indicators of compromise (IoCs) have been published, as Ivanti confirmed that there were no active attacks at the time of disclosure.
However, the ability to extract data via SQL injections could support broader campaigns, similar to previous incidents targeting management consoles.
Ivanti EPM 2024 SU3 SR1 and earlier versions are affected , with the 2022 branch no longer supported as of October 2025, leaving users without official support. For high-severity CVEs, fixes are scheduled for EPM 2024 SU4 , expected on November 12, 2025. SQL injections will follow in SU5 in Q1 2026. The delay is due to the complexity of resolving them without disrupting reporting features.
See also: PoC Exploit for Lenovo code execution vulnerability
Ivanti emphasized that upgrading to the latest 2024 release already significantly reduces risk through improved security controls. Customers on EOL releases face increased exposure and should upgrade immediately to avoid vulnerabilities.

Ways of protection
To address CVE-2025-11622, Ivanti recommends firewall whitelisting to block high-range TCP ports and restricting access to the central server to local EPM administrators only.
For CVE-2025-9713, users should avoid importing untrusted configuration files and thoroughly check those that need to be imported, as such actions carry inherent risks.
The SQL injection cluster can be addressed by removing the Reporting database user, although this disables the analysis features. Overall, staying on EPM 2024 SU3 SR1 or later provides some protections.
Ivanti's disclosure, despite pending fixes, prioritizes transparency, enabling proactive defenses in a landscape where endpoint administrators are prime targets for ransomware and APT groups . Organizations should review their EPM settings and consult Ivanti's Success Portal for personalized support.
