An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
Se presenta una vulnerabilidad de control de acceso inapropiado en Ivanti Avalanche versiones anteriores a 6.3.3, que permite a un atacante con acceso al Servicio Inforail llevar a cabo una toma de sesiĆ³n
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of JNLP files. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication on the system.