Security Advisory

CVE-2021-30497

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-04-06 01:22:07
Last updated 2024-08-03 22:32:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.