Multiple Vulnerabilities in Ivanti Cloud Services Application (CSA) Could Allow for Remote Code Execution
ID: cd072e2f-6b69-5b07-9832-fe5319cb5d46
STIX ID: report--cd072e2f-6b69-5b07-9832-fe5319cb5d46
Feed Name: CISecurity.org Advisories
**Ivanti CSA vulnerabilities (pre-5.0.3):** Multiple severe flaws were disclosed in Ivanti Cloud Services Application affecting the admin web console — an authentication bypass (CVE-2024-11639) enabling unauthenticated administrative access, a command injection (CVE-2024-11772) allowing remote code execution for authenticated admins, and a SQL injection (CVE-2024-11773) permitting arbitrary SQL execution; successful exploitation could lead to full system compromise and data manipulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
