
Cloud Vulnerability DB
A community-led vulnerabilities database
This vulnerability (CVE-2022-36972) affects Ivanti Avalanche version 6.3.2.3490 and allows remote attackers to bypass authentication. The vulnerability was discovered in the ProfileDaoImpl class and was publicly disclosed on March 29, 2023. The issue was initially reported to the vendor on October 22, 2021, and was tracked as ZDI-CAN-15328 (Zero Day Initiative).
The vulnerability exists within the ProfileDaoImpl class of Ivanti Avalanche. The specific flaw involves the execution of SQL queries composed from user-supplied strings, leading to SQL injection. The vulnerability has received a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).
An attacker can leverage this vulnerability to bypass authentication on the system, potentially gaining unauthorized access to sensitive information and system controls (Zero Day Initiative).
Ivanti has addressed this vulnerability in Avalanche version 6.3.4. Users are advised to upgrade to this version to protect against potential exploitation (Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."