First published: Thu Apr 04 2019(Updated: )
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported versions not listed here were not evaluated.
Credit: securityalerts@avaya.com securityalerts@avaya.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya IP Office Contact Center | >=9.0.0<=9.1.9 | |
Avaya IP Office Contact Center | >=10.0.0.0<=10.1.2.1 | |
>=9.0.0<=9.1.9 | ||
>=10.0.0.0<=10.1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7001 is a SQL injection vulnerability in the WebUI component of IP Office Contact Center.
CVE-2019-7001 allows an authenticated attacker to retrieve or alter sensitive data related to other users on the system by exploiting a SQL injection vulnerability in the WebUI component.
Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1.
CVE-2019-7001 has a severity rating of critical and a CVSS score of 8.8.
To fix CVE-2019-7001, update IP Office Contact Center to version 10.1.2.2.2-11201.1 or later.