VYPR
Critical severity9.8NVD Advisory· Published Apr 28, 2020· Updated Jun 17, 2026

CVE-2020-12442

CVE-2020-12442

Description

Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.

Affected products

3
  • Ivanti/Avalanche2 versions
    cpe:2.3:a:ivanti:avalanche:6.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ivanti:avalanche:6.3:*:*:*:*:*:*:*
    • (no CPE)range: <6.3
  • Ivanti/Avalanchedescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.