EUVD-2024-49897
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 9 Oct 2024. Evidence sources: cisa_kev.
- ENISA score
- 6.5 · CVSS 3.1
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2024-0399Kwetsbaarheden verholpen in Ivanti Cloud Services Appliance
