Improper Input Validation in EOL OVA Component by Saviynt
CVE-2025-3837
What is CVE-2025-3837?
An improper input validation flaw exists in the End of Life OVA based connect component deployed for installations within customer networks. This component was deprecated in September 2023, with support extended until January 2024. Under specific conditions, attackers may exploit this vulnerability by manipulating a request parameter, allowing them to inject malicious code, potentially leading to unauthorized remote code execution on the hosting infrastructure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OVA based Connect Linux AlmaLinux-8.x_SC2.0-Client-2.0
OVA based Connect Linux AlmaLinux-8.x_SC2.0-Client-3.0
OVA based Connect Linux CentOS-7.x_SC2.0-Client-2.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved