CVE-2018-8901: High severity Ivanti Avalanche vulnerability
Published Jun 29, 2018
·Updated
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.
Affected Software
1 affected component
Ivanti Avalanche>=5.3<=6.2
Event History
Jun 29, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-8901.
2
What is the severity of CVE-2018-8901?
The severity of CVE-2018-8901 is high with a score of 7.8.
3
Which versions of Ivanti Avalanche are affected?
All versions between 5.3 and 6.2 of Ivanti Avalanche are affected.
4
How can a local user with database access privileges exploit this vulnerability?
A local user with database access privileges can read the encrypted passwords for LDAP-authenticated users in Avalanche services.
5
Is there a fix available for CVE-2018-8901?
Please refer to the Ivanti community website for information on available fixes.