Vulnerabilities > Ivanti > Avalanche > 5.3.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-10 | CVE-2023-32565 | Unspecified vulnerability in Ivanti Avalanche An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | 9.1 |
2023-08-10 | CVE-2023-32566 | Unspecified vulnerability in Ivanti Avalanche An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | 9.1 |
2023-08-10 | CVE-2023-32567 | XXE vulnerability in Ivanti Avalanche Ivanti Avalanche decodeToMap XML External Entity Processing. | 9.8 |
2023-05-09 | CVE-2023-28127 | Path Traversal vulnerability in Ivanti Avalanche A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure. | 7.5 |
2023-05-09 | CVE-2023-28128 | Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. | 7.2 |
2023-03-10 | CVE-2022-44574 | Improper Authentication vulnerability in Ivanti Avalanche An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port. | 7.5 |
2021-12-07 | CVE-2021-42124 | Unspecified vulnerability in Ivanti Avalanche An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover. | 8.8 |
2021-12-07 | CVE-2021-42125 | Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files. | 8.8 |
2021-12-07 | CVE-2021-42126 | Unspecified vulnerability in Ivanti Avalanche An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. | 8.8 |
2021-12-07 | CVE-2021-42127 | Deserialization of Untrusted Data vulnerability in Ivanti Avalanche A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service. | 9.8 |