PT-2024-6877 · Ivanti · Ivanti Avalanche
Published
2024-04-17
·
Updated
2025-11-17
·
CVE-2024-47008
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ivanti Avalanche versions prior to 6.4.5
Description
A server-side request forgery issue exists in the
validateAMCWSConnection function of Ivanti Avalanche. This flaw allows a remote, unauthenticated attacker to disclose sensitive information by exploiting insufficient validation of incoming requests. The vulnerability impacts the ability to protect data handled by the system. The affected API endpoint is not specified. The vulnerable parameter is not specified.Recommendations
Versions prior to 6.4.5 should be updated to version 6.4.5 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Avalanche