CVE-2020-7032: Avaya WebLM Improper Restriction of XML External Entity Reference
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7032?
CVE-2020-7032 is an XML external entity (XXE) vulnerability in Avaya WebLM admin interface.
How does CVE-2020-7032 affect Avaya WebLM?
CVE-2020-7032 allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Which versions of Avaya WebLM are affected by CVE-2020-7032?
Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
What is the severity of CVE-2020-7032?
CVE-2020-7032 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2020-7032?
To fix CVE-2020-7032, it is recommended to apply the necessary updates and patches provided by Avaya.