Vulnerabilities
Vulnerable Software
Ivanti:  >> Xtraction  >> 2022.2  Security Vulnerabilities
Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
CVSS Score
7.7
EPSS Score
0.01
Published
2026-07-14
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
CVSS Score
4.0
EPSS Score
0.004
Published
2026-07-14
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.
CVSS Score
9.6
EPSS Score
0.009
Published
2026-05-12


Contact Us

Shodan ® - All rights reserved