漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Input Validation vulnerability in the End of Life (EOL) OVA based connect component
Vulnerability Description
An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Saviynt EOL OVA(Saviynt End of Life OVA) 安全漏洞
Vulnerability Description
Saviynt EOL OVA(Saviynt End of Life OVA)是Saviynt公司的一个生命周期组件。 Saviynt EOL OVA(Saviynt End of Life OVA)存在安全漏洞,该漏洞源于输入验证不当,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A