An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer component which is deployed for installation purposes in a customer network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. An actor can manipulate the action parameter of the login form to inject malicious scripts which would lead to a XSS attack under certain conditions.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12379 An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer component which is deployed for installation purposes in a customer network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. An actor can manipulate the action parameter of the login form to inject malicious scripts which would lead to a XSS attack under certain conditions.
Fixes

Solution

Follow this documentation link https://docs.saviyntcloud.com/bundle/Saviynt-Connect-20-Resources/page/Content/Saviynt-Connect-20-Client-Configurations.htm  and migrate to the latest version of Saviynt Connect component


Workaround

No workaround given by the vendor.

History

Mon, 21 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Apr 2025 10:00:00 +0000

Type Values Removed Values Added
Description An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer component which is deployed for installation purposes in a customer network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. An actor can manipulate the action parameter of the login form to inject malicious scripts which would lead to a XSS attack under certain conditions.
Title Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Saviynt

Published:

Updated: 2025-04-21T12:38:16.967Z

Reserved: 2025-04-21T09:34:01.701Z

Link: CVE-2025-3840

cve-icon Vulnrichment

Updated: 2025-04-21T12:38:05.573Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-21T10:15:15.643

Modified: 2025-04-21T14:23:45.950

Link: CVE-2025-3840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses