Improper Authentication in Avalanche - CVE-2023-46266
Published: January 15, 2024 / Updated: January 15, 2024
Avalanche
Ivanti
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper handling of the requested URI and accompanying Content-Type HTTP request header within the SecureFilter class. A remote attacker can bypass authentication process and gain unauthorized access to the application.