Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-8901

Опубликовано: 29 июн. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 2.1
EPSS Низкий

Описание

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*
Версия от 5.3 (включая) до 6.2 (включая)

EPSS

Процентиль: 35%
0.00143
Низкий

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.

EPSS

Процентиль: 35%
0.00143
Низкий

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

NVD-CWE-noinfo