CVE-2019-7007: Avaya Equinox Conferencing Management (iView) Directory Traversal Vulnerability
A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2019-7007.
What is the affected software?
The affected software is Avaya Equinox Management(iView) versions R9.1.9.0 and earlier.
What is the severity of CVE-2019-7007?
The severity of CVE-2019-7007 is high, with a severity value of 8.6.
What is the potential impact of exploiting CVE-2019-7007?
Exploiting CVE-2019-7007 could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.
Is there a fix available for this vulnerability?
Please refer to the Avaya advisory at the following link for information on the fix: [Avaya Advisory](https://downloads.avaya.com/css/P8/documents/101064450)