CVE-2020-12442: SQL Injection
Published Apr 28, 2020
·Updated
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.
Affected Software
1 affected component
Ivanti Avalanche=6.3
Event History
Apr 28, 2020
CVE Published
via MITRE·09:54 PM
Data Sourced
via MITRE·09:54 PM
Description
Frequently Asked Questions
1
What is CVE-2020-12442?
CVE-2020-12442 is a vulnerability in Ivanti Avalanche 6.3 that allows SQL injection.
2
What is the severity of CVE-2020-12442?
The severity of CVE-2020-12442 is critical (9.8).
3
How does CVE-2020-12442 affect Ivanti Avalanche 6.3?
CVE-2020-12442 affects Ivanti Avalanche 6.3 by allowing SQL injection.
4
How can I fix CVE-2020-12442?
To fix CVE-2020-12442, update Ivanti Avalanche to a version that includes a patch for this vulnerability.
5
Where can I find more information about CVE-2020-12442?
For more information about CVE-2020-12442, you can visit the Ivanti forums article at https://forums.ivanti.com/s/article/SQL-Injection-Vulnerability-in-Avalanche.