PT-2024-1727 · Ivanti · Ivanti Avalanche

Jbalanza

·

Published

2024-01-25

·

Updated

2024-01-31

·

CVE-2023-41474

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche version 6.3.4.153
Description The issue is related to a Directory Traversal vulnerability in the javax.faces.resource component, which can be exploited by a remote authenticated attacker to obtain sensitive information. This vulnerability is due to incorrect restriction of the directory path name with limited access.
Recommendations For Ivanti Avalanche version 6.3.4.153, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-01433
CVE-2023-41474

Affected Products

Ivanti Avalanche