Saviynt End-of-Life OVA Component Remote Code Execution Vulnerability

Vulnerability

A vulnerability allowing remote code execution has been identified in a deprecated OVA-based component of Saviynt, which is used for installation on internal customer networks. This component reached its end of life in September 2023, with support extended until January 2024. The vulnerability arises from improper input validation, which allows an actor to manipulate a request parameter and inject a payload that could be executed on the host infrastructure.

Impact

Exploitation of this vulnerability allows for remote code execution on the infrastructure hosting the affected Saviynt component.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.