Vulnerabilities > Ivanti > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-07 | CVE-2021-42125 | Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files. | 6.5 |
2021-12-07 | CVE-2021-42126 | Unspecified vulnerability in Ivanti Avalanche An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. | 6.5 |
2021-12-07 | CVE-2021-42129 | Command Injection vulnerability in Ivanti Avalanche A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. | 6.5 |
2021-12-07 | CVE-2021-42130 | Deserialization of Untrusted Data vulnerability in Ivanti Avalanche A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution. | 6.5 |
2021-12-07 | CVE-2021-42131 | SQL Injection vulnerability in Ivanti Avalanche A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. | 6.5 |
2021-12-07 | CVE-2021-42132 | Command Injection vulnerability in Ivanti Avalanche A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. | 6.5 |
2021-12-07 | CVE-2021-42133 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ivanti Avalanche An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write. | 5.5 |
2021-09-01 | CVE-2021-36235 | Unspecified vulnerability in Ivanti Workspace Control An issue was discovered in Ivanti Workspace Control before 10.6.30.0. | 4.6 |
2021-08-16 | CVE-2021-22933 | Path Traversal vulnerability in multiple products A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request. | 6.5 |
2021-08-16 | CVE-2021-22936 | Cross-site Scripting vulnerability in multiple products A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter. | 6.1 |