CVE-2023-41474: Ivanti Avalanche

Medium severity, CVSS 6.5. EPSS: 37.6% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

Affected products

  • Ivanti Avalanche: version 6.3.4.153 only

Published 2024-01-25. Last modified 2026-06-17.