CVE-2019-7001: Avaya IPOCC WebUI SQL Injection
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported versions not listed here were not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7001?
CVE-2019-7001 is a SQL injection vulnerability in the WebUI component of IP Office Contact Center.
How does CVE-2019-7001 work?
CVE-2019-7001 allows an authenticated attacker to retrieve or alter sensitive data related to other users on the system by exploiting a SQL injection vulnerability in the WebUI component.
Which versions of IP Office Contact Center are affected by CVE-2019-7001?
Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1.
What is the severity of CVE-2019-7001?
CVE-2019-7001 has a severity rating of critical and a CVSS score of 8.8.
How can I fix CVE-2019-7001?
To fix CVE-2019-7001, update IP Office Contact Center to version 10.1.2.2.2-11201.1 or later.