Ivanti Avalanche
cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*
- <= 6.4.6
A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to bypass authentication, addressing incomplete fixes from a previous vulnerability (CVE-2024-47010).
Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access or actions within the application.
Users can upgrade to Ivanti Avalanche version 6.4.7. This release is a full product install, and an in-place upgrade can be performed according to the product documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.