Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
According to CWE-201 classification (Insertion of Sensitive Information Into Sent Data), the application incorrectly includes sensitive data in sent network requests or responses. An attacker with administrative privileges (PR:H) can exploit this vulnerability remotely over the network (AV:N) without user interaction. The vulnerability has a scope extending beyond the application context (S:C), which increases its criticality.
An attacker can gain unauthorized access to sensitive information processed by the application, and successful exploitation can lead to complete breach of confidentiality, integrity, and availability of the system and resources beyond the application itself.
Netwrix Directory Manager should be updated to version 11.1.25134.03, which according to the vendor's description is not vulnerable. Detailed update instructions are available in the official vendor security advisory at the address indicated in the references (ADV-2025-014).
Netwrix Directory Manager (formerly Imanami GroupID) in version 11.0.0.0 and earlier, as well as in versions after 11.1.25134.03
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HNetwrix Directory Manager
APPNetwrix11.0.0.0 – 11.1.25134.03 (excl.)
Related vulnerabilities
Zakodowane na stałe hasło w Netwrix Directory Manager (CVE-2025-48748)
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Informati...
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protecte...
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authenticati...
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authe...