CVE-2023-32567: XEE
Published Aug 10, 2023
·Updated
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.
Affected Software
1 affected component
Ivanti Avalanche<6.4.1
Event History
Aug 10, 2023
CVE Published
06:58 PM
Data Sourced
06:58 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-32567?
CVE-2023-32567 is a vulnerability in Ivanti Avalanche that allows XML External Entity (XXE) processing, which can lead to unauthorized access to sensitive information.
2
What is the severity of CVE-2023-32567?
The severity of CVE-2023-32567 is critical, with a CVSS score of 9.8.
3
How does CVE-2023-32567 affect Ivanti Avalanche?
CVE-2023-32567 affects Ivanti Avalanche by exploiting XML External Entity (XXE) processing, which can result in unauthorized access to sensitive data.
4
Has CVE-2023-32567 been fixed?
Yes, CVE-2023-32567 has been fixed in Ivanti Avalanche version 6.4.1.
5
Where can I find more information about CVE-2023-32567?
You can find more information about CVE-2023-32567 on the Ivanti forums at https://forums.ivanti.com/s/article/Avalanche-Vulnerabilities-Addressed-in-6-4-1?language=en_US.