CVE-2020-12442
https://notcve.org/view.php?id=CVE-2020-12442
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250. Ivanti Avalanche versión 6.3, permite una inyección SQL que está vagamente asociada con el Servidor Apache HTTP, también se conoce como Bug 683250. • https://forums.ivanti.com/s/article/SQL-Injection-Vulnerability-in-Avalanche • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2018-8902
https://notcve.org/view.php?id=CVE-2018-8902
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product. Se ha descubierto un problema en Ivanti Avalanche para todas las versiones entre la 5.3 y la 6.2. • https://community.ivanti.com/docs/DOC-68406 • CWE-287: Improper Authentication •
CVE-2018-8901
https://notcve.org/view.php?id=CVE-2018-8901
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration. Se ha descubierto un problema en Ivanti Avalanche para todas las versiones entre la 5.3 y la 6.2. • https://community.ivanti.com/docs/DOC-68406 •