First published: Fri Nov 13 2020(Updated: )
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
Credit: securityalerts@avaya.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Aura System Manager | >=7.0<=7.1.3.6 | |
Avaya Aura System Manager | >=8.0<=8.1.2 | |
Avaya WebLM | >=7.0<=7.1.3.6 | |
Avaya WebLM | >=8.0.0<8.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7032 is an XML external entity (XXE) vulnerability in Avaya WebLM admin interface.
CVE-2020-7032 allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
CVE-2020-7032 has a severity rating of 6.5, which is considered medium.
To fix CVE-2020-7032, it is recommended to apply the necessary updates and patches provided by Avaya.