PT-2024-7353 · Ivanti · Ivanti Cloud Services Appliance

Published

2024-10-08

·

Updated

2025-07-18

·

CVE-2024-9379

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ivanti Cloud Services Appliance versions prior to 5.0.2
Description: The issue is related to a SQL injection vulnerability in the admin web console of Ivanti Cloud Services Appliance. This vulnerability allows a remote authenticated attacker with admin privileges to execute arbitrary SQL statements. The vulnerability is being actively exploited in the wild.
Recommendations: For versions prior to 5.0.2, update to version 5.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin web console to minimize the risk of exploitation. Avoid using the vulnerable SQL functionality in the admin web console until the issue is resolved.

Fix

Path traversal

SQL injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-08715
BDU:2024-08716
BDU:2024-08717
CVE-2024-9379

Affected Products

Ivanti Cloud Services Appliance