SQL Injection Vulnerability in Ivanti Avalanche
CVE-2021-42131
8.8HIGH
Summary
A SQL Injection vulnerability has been identified in Ivanti Avalanche versions prior to 6.3.3. This issue permits an attacker with access to the Inforail Service to execute unauthorized SQL commands, ultimately leading to potential privilege escalation. It is crucial for users of the affected software to update to the latest version to safeguard against this type of vulnerability and protect their systems from exploitation.
Affected Version(s)
Ivanti Avalanche 6.3.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved