An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://saviynt.com/trust-compliance-security |
Configurations
No configuration.
History
21 Apr 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-21 10:15
Updated : 2025-04-21 14:23
NVD link : CVE-2025-3838
Mitre link : CVE-2025-3838
CVE.ORG link : CVE-2025-3838
JSON object : View
Products Affected
No product.