SQL Injection Vulnerability in Ivanti Avalanche
CVE-2021-42131

8.8HIGH

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
7 December 2021

Summary

A SQL Injection vulnerability has been identified in Ivanti Avalanche versions prior to 6.3.3. This issue permits an attacker with access to the Inforail Service to execute unauthorized SQL commands, ultimately leading to potential privilege escalation. It is crucial for users of the affected software to update to the latest version to safeguard against this type of vulnerability and protect their systems from exploitation.

Affected Version(s)

Ivanti Avalanche 6.3.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.