PT-2024-1727 · Ivanti · Ivanti Avalanche
Jbalanza
·
Published
2024-01-25
·
Updated
2024-01-31
·
CVE-2023-41474
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ivanti Avalanche version 6.3.4.153
Description
The issue is related to a Directory Traversal vulnerability in the javax.faces.resource component, which can be exploited by a remote authenticated attacker to obtain sensitive information. This vulnerability is due to incorrect restriction of the directory path name with limited access.
Recommendations
For Ivanti Avalanche version 6.3.4.153, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Avalanche