Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-7001

Опубликовано: 04 апр. 2019
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported versions not listed here were not evaluated.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:avaya:ip_office_contact_center:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.1.9 (включая)
cpe:2.3:a:avaya:ip_office_contact_center:*:*:*:*:*:*:*:*
Версия от 10.0.0.0 (включая) до 10.1.2.1 (включая)

EPSS

Процентиль: 53%
0.00296
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported versions not listed here were not evaluated.

EPSS

Процентиль: 53%
0.00296
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89