Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-36975

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15332.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 83.2%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2022-36975
  • Ivanti » Avalanche » Version: 6.3.2.3490
    cpe:2.3:a:ivanti:avalanche:6.3.2.3490
  • Ivanti » Avalanche » Version: 6.3.3
    cpe:2.3:a:ivanti:avalanche:6.3.3
  • Ivanti » Avalanche » Version: 6.3.3.101
    cpe:2.3:a:ivanti:avalanche:6.3.3.101


Contact Us

Shodan ® - All rights reserved