Описание
SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.8.8008 (исключая)
cpe:2.3:a:ivanti:avalanche:*:*:*:*:premise:*:*:*
EPSS
Процентиль: 85%
0.02343
Низкий
7.2 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 7.2
github
6 месяцев назад
SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution
EPSS
Процентиль: 85%
0.02343
Низкий
7.2 High
CVSS3
Дефекты
CWE-89