CVE-2020-7035: XXE in Avaya Aura Orchestration Designer
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7035?
CVE-2020-7035 is an XML External Entities (XXE) vulnerability in the web-based user interface of Avaya Aura Orchestration Designer.
How can an attacker exploit CVE-2020-7035?
An authenticated, remote attacker can exploit CVE-2020-7035 to gain read access to information stored on the affected system.
What versions of Avaya Aura Orchestration Designer are affected by CVE-2020-7035?
All 7.x versions of Avaya Aura Orchestration Designer including 7.0 to 7.2.2 are affected by CVE-2020-7035.
What is the severity rating of CVE-2020-7035?
CVE-2020-7035 has a severity rating of 6.5 (high).
Is there a fix available for CVE-2020-7035?
Avaya has released a fix for CVE-2020-7035. Please refer to the vendor's advisory for more information.