Vulnerabilities > Ivanti

DATE CVE VULNERABILITY TITLE RISK
2021-12-15 CVE-2019-19138 Unspecified vulnerability in Ivanti Workspace Control
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
network
low complexity
ivanti
7.5
2021-12-08 CVE-2021-44529 Code Injection vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.5/4.6
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
network
low complexity
ivanti CWE-94
critical
9.8
2021-12-07 CVE-2021-42124 Unspecified vulnerability in Ivanti Avalanche
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
network
low complexity
ivanti
8.8
2021-12-07 CVE-2021-42125 Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
network
low complexity
ivanti CWE-434
8.8
2021-12-07 CVE-2021-42126 Unspecified vulnerability in Ivanti Avalanche
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
network
low complexity
ivanti
8.8
2021-12-07 CVE-2021-42127 Deserialization of Untrusted Data vulnerability in Ivanti Avalanche
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
network
low complexity
ivanti CWE-502
critical
9.8
2021-12-07 CVE-2021-42128 Unspecified vulnerability in Ivanti Avalanche
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
network
low complexity
ivanti
critical
9.8
2021-12-07 CVE-2021-42129 Command Injection vulnerability in Ivanti Avalanche
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
network
low complexity
ivanti CWE-77
8.8
2021-12-07 CVE-2021-42130 Deserialization of Untrusted Data vulnerability in Ivanti Avalanche
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
network
low complexity
ivanti CWE-502
8.8
2021-12-07 CVE-2021-42131 SQL Injection vulnerability in Ivanti Avalanche
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
network
low complexity
ivanti CWE-89
8.8