CVE-2020-7032
13.11.2020, 01:15
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.Enginsight
Vendor | Product | Version |
---|---|---|
avaya | aura_system_manager | 7.0 ≤ 𝑥 ≤ 7.1.3.6 |
avaya | aura_system_manager | 8.0 ≤ 𝑥 ≤ 8.1.2 |
avaya | weblm | 7.0 ≤ 𝑥 ≤ 7.1.3.6 |
avaya | weblm | 8.0.0 ≤ 𝑥 < 8.1.3 |
𝑥
= Vulnerable software versions
References