Vulnerabilities > Ivanti > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-01 CVE-2021-38560 Cross-site Scripting vulnerability in Ivanti Service Manager 2021.1
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
network
ivanti CWE-79
4.3
2021-12-15 CVE-2019-19138 Unspecified vulnerability in Ivanti Workspace Control
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
network
low complexity
ivanti
5.0
2021-12-07 CVE-2021-42124 Unspecified vulnerability in Ivanti Avalanche
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
network
low complexity
ivanti
6.5
2021-12-07 CVE-2021-42125 Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
network
low complexity
ivanti CWE-434
6.5
2021-12-07 CVE-2021-42126 Unspecified vulnerability in Ivanti Avalanche
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
network
low complexity
ivanti
6.5
2021-12-07 CVE-2021-42129 Command Injection vulnerability in Ivanti Avalanche
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
network
low complexity
ivanti CWE-77
6.5
2021-12-07 CVE-2021-42130 Deserialization of Untrusted Data vulnerability in Ivanti Avalanche
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
network
low complexity
ivanti CWE-502
6.5
2021-12-07 CVE-2021-42131 SQL Injection vulnerability in Ivanti Avalanche
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
network
low complexity
ivanti CWE-89
6.5
2021-12-07 CVE-2021-42132 Command Injection vulnerability in Ivanti Avalanche
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
network
low complexity
ivanti CWE-77
6.5
2021-12-07 CVE-2021-42133 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ivanti Avalanche
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.
network
low complexity
ivanti CWE-829
5.5