PT-2024-7353 · Ivanti · Ivanti Cloud Services Appliance
Published
2024-10-08
·
Updated
2025-07-18
·
CVE-2024-9379
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Ivanti Cloud Services Appliance versions prior to 5.0.2
Description:
The issue is related to a SQL injection vulnerability in the admin web console of Ivanti Cloud Services Appliance. This vulnerability allows a remote authenticated attacker with admin privileges to execute arbitrary SQL statements. The vulnerability is being actively exploited in the wild.
Recommendations:
For versions prior to 5.0.2, update to version 5.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin web console to minimize the risk of exploitation. Avoid using the vulnerable SQL functionality in the admin web console until the issue is resolved.
Fix
Path traversal
SQL injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Cloud Services Appliance