VendorsNetwrixdirectory_managerall versions
Vulnerabilities

Netwrix Directory Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2025-48748
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
Published 2025-05-29 · Analyzed
10.0EPSS 0.004
CVE-2025-48749
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
Published 2025-05-28 · Analyzed
9.1EPSS 0.004
CVE-2025-48746
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.
Published 2025-05-28 · Analyzed
6.5EPSS 0.003
CVE-2025-54392
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.
Published 2025-08-07 · Analyzed
6.1EPSS 0.003
CVE-2025-54395
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.
Published 2025-08-07 · Analyzed
6.1EPSS 0.003
CVE-2025-54393
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.
Published 2025-08-07 · Analyzed
5.4EPSS 0.002
CVE-2025-54396
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.
Published 2025-08-07 · Analyzed
5.4EPSS 0.002
CVE-2025-47748
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
Published 2025-05-28 · Analyzed
5.3EPSS 0.003
CVE-2025-54394
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.
Published 2025-08-07 · Analyzed
5.3EPSS 0.003
CVE-2025-48747
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.
Published 2025-05-28 · Analyzed
5.0EPSS 0.003
CVE-2025-54397
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.
Published 2025-08-07 · Analyzed
4.3EPSS 0.003