OpsBuzz

Alert

Ivanti Cloud Services Appliance CSA SQL Injection Vulnerability

Ivanti Cloud Services Appliance CSA contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote at

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.

Vendor: Ivanti

Product: Cloud Services Appliance (CSA)

Due date: 2024-10-30

Known ransomware use: Unknown

Why it matters

As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Related alerts

Ivanti Cloud Services Appliance CSA SQL Injection Vulnerability | OpsBuzz