CVE-2023-7031: Avaya Experience Portal Manager Insecure Direct Object Reference Vulnerabilities
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 patch 0402. Versions prior to 8.0 are end of manufacturer support.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7031?
CVE-2023-7031 is categorized as a low to medium severity vulnerability due to the potential for partial information disclosure to authenticated users.
How do I fix CVE-2023-7031?
To mitigate CVE-2023-7031, users should update to Avaya Aura Experience Portal versions 8.1.2 patch 0402 or later.
What are the affected versions in CVE-2023-7031?
The affected versions in CVE-2023-7031 are Avaya Aura Experience Portal 8.0.x and 8.1.x prior to 8.1.2 patch 0402.
What type of vulnerability is CVE-2023-7031?
CVE-2023-7031 is classified as an Insecure Direct Object Reference vulnerability.
Who is at risk from CVE-2023-7031?
Authenticated non-privileged users of Avaya Aura Experience Portal could be at risk of partial information disclosure due to CVE-2023-7031.