CVE-2021-42125 – Ivanti Avalanche Filestore Management Arbitrary File Upload Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-42125
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files. Se presenta una vulnerabilidad de carga de archivos sin restricciones en Ivanti Avalanche versiones anteriores a 6.3.3, que permite a un atacante con acceso al Servicio Inforail escribir archivos peligrosos This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche. Authentication is required to exploit this vulnerability. The specific flaw exists within the FileStoreConfig app. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the service account. • https://forums.ivanti.com/s/article/Security-Alert-CVE-s-Addressed-in-Avalanche-6-3-3 • CWE-434: Unrestricted Upload of File with Dangerous Type CWE-502: Deserialization of Untrusted Data •
CVE-2020-12442
https://notcve.org/view.php?id=CVE-2020-12442
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250. Ivanti Avalanche versión 6.3, permite una inyección SQL que está vagamente asociada con el Servidor Apache HTTP, también se conoce como Bug 683250. • https://forums.ivanti.com/s/article/SQL-Injection-Vulnerability-in-Avalanche • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2018-8902
https://notcve.org/view.php?id=CVE-2018-8902
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product. Se ha descubierto un problema en Ivanti Avalanche para todas las versiones entre la 5.3 y la 6.2. • https://community.ivanti.com/docs/DOC-68406 • CWE-287: Improper Authentication •
CVE-2018-8901
https://notcve.org/view.php?id=CVE-2018-8901
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration. Se ha descubierto un problema en Ivanti Avalanche para todas las versiones entre la 5.3 y la 6.2. • https://community.ivanti.com/docs/DOC-68406 •