CVE-2021-22962: Critical severity ivanti avalanche vulnerability
Published Dec 19, 2023
·Updated
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
Affected Software
1 affected component
Ivanti Avalanche<6.4.2
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2021-22962?
CVE-2021-22962 is considered a medium severity vulnerability due to its potential to leak sensitive data and cause a resource-based denial of service.
2
How do I fix CVE-2021-22962?
To fix CVE-2021-22962, ensure that you update Ivanti Avalanche to version 6.4.2 or later.
3
What types of attacks does CVE-2021-22962 enable?
CVE-2021-22962 enables attackers to perform data leakage and potentially execute resource-based denial of service attacks.
4
Which versions of Ivanti Avalanche are affected by CVE-2021-22962?
CVE-2021-22962 affects all versions of Ivanti Avalanche prior to 6.4.2.
5
What is the impact of exploiting CVE-2021-22962?
Exploiting CVE-2021-22962 can lead to the leakage of sensitive data or a denial of service condition affecting the application.