CVE-2024-9379: Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.
Other sources
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Cloud Service Appliance (CSA)to a version that resolves this vulnerability.Fixed in 5.0.2 - Remove
Remove
Ivanti Cloud Service Appliance (CSA) 4.6.xfrom your environment.Remove CSA 4.6.x from service.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9379?
CVE-2024-9379 is considered to be a high severity vulnerability due to the potential for remote exploitation via SQL injection.
How do I fix CVE-2024-9379?
To fix CVE-2024-9379, it is recommended to upgrade the Ivanti Cloud Services Appliance to version 5.0.2 or later.
Who is affected by CVE-2024-9379?
CVE-2024-9379 affects users of Ivanti Cloud Services Appliance versions prior to 5.0.2.
Can CVE-2024-9379 be exploited remotely?
Yes, CVE-2024-9379 can be exploited remotely by an authenticated administrator to execute arbitrary SQL statements.
What type of vulnerability is CVE-2024-9379?
CVE-2024-9379 is a SQL injection vulnerability found in the admin web console of the Ivanti Cloud Services Appliance.