Vulnerabilities > Ivanti

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-22572 Unspecified vulnerability in Ivanti Incapptic Connect
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality.
network
low complexity
ivanti
8.8
2022-04-11 CVE-2022-27088 Unquoted Search Path or Element vulnerability in Ivanti DSM Remote
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
local
low complexity
ivanti CWE-428
7.8
2022-04-06 CVE-2021-30497 Path Traversal vulnerability in Ivanti Avalanche 6.3.2
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal.
network
low complexity
ivanti CWE-22
7.5
2022-03-04 CVE-2022-21828 Unspecified vulnerability in Ivanti Incapptic Connect
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.
network
low complexity
ivanti
7.2
2022-02-01 CVE-2021-38560 Cross-site Scripting vulnerability in Ivanti Service Manager 2021.1
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
network
low complexity
ivanti CWE-79
6.1
2022-01-10 CVE-2022-21823 Insecure Storage of Sensitive Information vulnerability in Ivanti Workspace Control
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
local
low complexity
ivanti CWE-922
5.5
2021-12-15 CVE-2019-19138 Unspecified vulnerability in Ivanti Workspace Control
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
network
low complexity
ivanti
7.5
2021-12-08 CVE-2021-44529 Code Injection vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.5/4.6
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
network
low complexity
ivanti CWE-94
critical
9.8
2021-12-07 CVE-2021-42124 Unspecified vulnerability in Ivanti Avalanche
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
network
low complexity
ivanti
8.8
2021-12-07 CVE-2021-42125 Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
network
low complexity
ivanti CWE-434
8.8