Vulnerabilities > Ivanti > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-50331 Out-of-bounds Read vulnerability in Ivanti Avalanche
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
network
low complexity
ivanti CWE-125
7.5
2024-11-12 CVE-2024-8495 NULL Pointer Dereference vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
network
low complexity
ivanti CWE-476
7.5
2024-11-12 CVE-2024-9420 Use After Free vulnerability in Ivanti Connect Secure 7.1/7.4
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
network
low complexity
ivanti CWE-416
8.8
2024-10-08 CVE-2024-47007 NULL Pointer Dereference vulnerability in Ivanti Avalanche
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
network
low complexity
ivanti CWE-476
7.5
2024-10-08 CVE-2024-47008 Server-Side Request Forgery (SSRF) vulnerability in Ivanti Avalanche
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
network
low complexity
ivanti CWE-918
7.5
2024-10-08 CVE-2024-47011 Path Traversal vulnerability in Ivanti Avalanche
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
network
low complexity
ivanti CWE-22
7.5
2024-10-08 CVE-2024-7612 Incorrect Permission Assignment for Critical Resource vulnerability in Ivanti Endpoint Manager Mobile
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
local
low complexity
ivanti CWE-732
7.8
2024-10-08 CVE-2024-9379 SQL Injection vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.5/4.6
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
network
low complexity
ivanti CWE-89
7.2
2024-10-08 CVE-2024-9380 OS Command Injection vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.5/4.6
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
network
low complexity
ivanti CWE-78
7.2
2024-10-08 CVE-2024-9381 Path Traversal vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.5/4.6
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
network
low complexity
ivanti CWE-22
7.2