CVE-2024-9379: Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2024-10-09. EPSS: 43.8% chance of exploitation in the next 30 days.

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

Affected products

  • Ivanti Endpoint Manager Cloud Services Appliance: before 5.0.2 (fixed in 5.0.2)

Published 2024-10-08. Last modified 2026-10-01.