CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-11773

CVSS 9.1v3.1pub. 2024-12-10upd. 2025-01-17

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

🤖 AI Analysis
How it works

An attacker with access to the administration console can inject malicious SQL code into vulnerable fields of the web interface. The application does not properly filter input data before passing it to the database engine, allowing the construction and execution of arbitrary SQL queries. This makes it possible to read, modify, or delete data stored in the database, and potentially also execute system operations depending on the database server configuration.

Impact

An attacker can read, modify, or delete any data in the application database, leading to complete compromise of system confidentiality and integrity. Depending on the environment configuration, disruption of service availability is also possible.

Mitigation & patch

Ivanti Cloud Services Appliance must be updated to version 5.0.3 or newer in accordance with the manufacturer's recommendations published in the Ivanti security advisory.

Who is affected

Ivanti Cloud Services Appliance (CSA) in all versions prior to 5.0.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Ivanti Cloud Services Appliance

    APP
    Ivanti
    < 5.0.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-47908CRITICAL9.1PL ✓same product

OS command injection w Ivanti CSA — RCE dla admina

CVE-2024-11639CRITICAL10.0PL ✓same product

Authentication bypass w panelu admina Ivanti CSA — pełny dostęp bez logowania

CVE-2024-11772CRITICAL9.1PL ✓same product

Command injection w konsoli administracyjnej Ivanti CSA umożliwia RCE

CVE-2024-8190HIGH7.2⚠ KEVsame product

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before all...

CVE-2025-22460HIGH7.8same product

Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated att...