NA
CVSSv3

CVE-2025-3840

CVSSv4: 2.1 | CVSSv3: NA | CVSSv2: NA | VMScore: 310 | EPSS: 0.00033 | KEV: Not Included
Published: 21/04/2025 Updated: 21/04/2025

Vulnerability Summary

Cross-Site Scripting (XSS) Vulnerability in End of Life OVA Connect Installer

An End of Life (EOL) OVA based connect installer component, used for network installation, has a vulnerability involving improper neutralization of input. This deprecated component, which was phased out in September 2023 with support ending in January 2024, allows an actor to manipulate the login form's action parameter. By injecting malicious scripts through this parameter, an attacker could potentially execute a Cross Site Scripting (XSS) attack under specific conditions.

Solution

Follow this documentation link https://docs.saviyntcloud.com/bundle/Saviynt-Connect-20-Resources/page/Content/Saviynt-Connect-20-Client-Configurations.htm  and migrate to the latest version of Saviynt Connect component

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

saviynt ova based connect