First published: Thu Jun 24 2021(Updated: )
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
Credit: securityalerts@avaya.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Aura Experience Portal | >=7.0<=7.2.3 | |
Avaya Aura Experience Portal | =8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Avaya Aura Experience Portal vulnerability is CVE-2021-25655.
CVE-2021-25655 has a severity rating of 6.1 (medium severity).
CVE-2021-25655 affects the system Service Menu component of Avaya Aura Experience Portal.
Affected versions of Avaya Aura Experience Portal include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
To fix CVE-2021-25655, you should apply the necessary hotfix for affected versions of Avaya Aura Experience Portal.