Description
Ivanti CSA contains a path traversal vulnerability that could allow an unauthenticated attacker to access restricted functionality and exploit the RCE vulnerability, CVE-2024-8190, to compromise the system.
Remediation
Upgrade to the latest version of Ivanti CSA.
References
Security Advisory Ivanti CSA 4.6 (Cloud Services Appliance) (CVE-2024-8963)
Security Advisory Ivanti Cloud Service Appliance (CSA) (CVE-2024-8190)
Burning Zero Days: Suspected Nation-State Adversary Targets Ivanti CSA
Related Vulnerabilities
Oracle Application Server CVE-2008-7235 Vulnerability (CVE-2008-7235)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6105)
Oracle JRE CVE-2018-2641 Vulnerability (CVE-2018-2641)
PostgreSQL Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-1899)