An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12380 An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.
Fixes

Solution

Follow this documentation link https://docs.saviyntcloud.com/bundle/Saviynt-Connect-20-Resources/page/Content/Saviynt-Connect-20-Client-Configurations.htm  and migrate to the latest version of Saviynt Connect component


Workaround

No workaround given by the vendor.

History

Mon, 21 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Apr 2025 09:30:00 +0000

Type Values Removed Values Added
Description An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.
Title Improper Input Validation vulnerability in the End of Life (EOL) OVA based connect component
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Saviynt

Published:

Updated: 2025-04-21T13:05:14.280Z

Reserved: 2025-04-21T08:33:27.146Z

Link: CVE-2025-3837

cve-icon Vulnrichment

Updated: 2025-04-21T12:53:59.234Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-21T10:15:15.207

Modified: 2025-04-21T14:23:45.950

Link: CVE-2025-3837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses