First published: Tue Apr 28 2020(Updated: )
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Avalanche | =6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12442 is a vulnerability in Ivanti Avalanche 6.3 that allows SQL injection.
The severity of CVE-2020-12442 is critical (9.8).
CVE-2020-12442 affects Ivanti Avalanche 6.3 by allowing SQL injection.
To fix CVE-2020-12442, update Ivanti Avalanche to a version that includes a patch for this vulnerability.
For more information about CVE-2020-12442, you can visit the Ivanti forums article at https://forums.ivanti.com/s/article/SQL-Injection-Vulnerability-in-Avalanche.