Input Handling Flaw in End of Life OVA Installer by Saviynt
CVE-2025-3840
What is CVE-2025-3840?
A significant input handling flaw has been discovered in Saviynt's End of Life OVA based connect installer. This vulnerability allows an attacker to manipulate the action parameter of the login form, potentially leading to Cross-Site Scripting (XSS) attacks. Although the component was deprecated in September 2023, its support extends until January 2024, thus posing ongoing risks to affected systems. Implementing proper input validation and sanitization practices is critical in mitigating the likelihood of such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OVA based Connect Linux AlmaLinux-8.x_SC2.0-Client-2.0
OVA based Connect Linux AlmaLinux-8.x_SC2.0-Client-3.0
OVA based Connect Linux CentOS-7.x_SC2.0-Client-2.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved