Ivanti CSA
cpe:2.3:a:ivanti:endpoint_manager_cloud_services_appliance:*:*:*:*:*:*:*
- <= 5.0.1
This vulnerability is being actively exploited in the wild.
A SQL injection vulnerability has been identified in the admin web console of Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary SQL statements. While exploitation of this vulnerability in CSA 5.0 has not been observed, it has been exploited in CSA 4.6 when chained with another vulnerability, leading to unauthorized remote code execution.
Exploitation of this vulnerability allows for arbitrary SQL execution, which could be used to manipulate the database or extract sensitive information.
Users are advised to upgrade to Ivanti Cloud Services Appliance version 5.0.2. Instructions for downloading this version are available in the Ivanti Cloud Services Application 5.0.2 Download Release Notes Patch History.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.