Описание
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.0 (включая) до 7.1.3.6 (включая)Версия от 8.0 (включая) до 8.1.2 (включая)Версия от 7.0 (включая) до 7.1.3.6 (включая)Версия от 8.0.0 (включая) до 8.1.3 (исключая)
Одно из
cpe:2.3:a:avaya:aura_system_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:avaya:aura_system_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:avaya:weblm:*:*:*:*:*:*:*:*
cpe:2.3:a:avaya:weblm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00659
Низкий
6.5 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-611
CWE-611
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
EPSS
Процентиль: 71%
0.00659
Низкий
6.5 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-611
CWE-611