An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.
History

Mon, 21 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Apr 2025 09:30:00 +0000

Type Values Removed Values Added
Description An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.
Title Improper Input Validation vulnerability in the End of Life (EOL) OVA based connect component
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Saviynt

Published: 2025-04-21T09:20:14.110Z

Updated: 2025-04-21T13:05:14.280Z

Reserved: 2025-04-21T08:33:27.146Z

Link: CVE-2025-3837

cve-icon Vulnrichment

Updated: 2025-04-21T12:53:59.234Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-21T10:15:15.207

Modified: 2025-04-21T14:23:45.950

Link: CVE-2025-3837

cve-icon Redhat

No data.