An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
2020-11-13T01:15:11.917
2024-11-21T05:36:31.117
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | avaya | aura_system_manager | ≤ 7.1.3.6 | Yes |
Application | avaya | aura_system_manager | ≤ 8.1.2 | Yes |
Application | avaya | weblm | ≤ 7.1.3.6 | Yes |
Application | avaya | weblm | < 8.1.3 | Yes |