Avaya WebLM Improper Restriction of XML External Entity Reference
Vulnerability Description
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-7032
Credits & Attribution
No credits recorded in the NVD database.
References
- https://downloads.avaya.com/css/P8/documents/101072249
- http://seclists.org/fulldisclosure/2020/Nov/31
- http://packetstormsecurity.com/files/160123/Avaya-Web-License-Manager-XML-Injection.html
- https://sec-consult.com/vulnerability-lab/advisory/blind-out-of-band-xml-external-entity-injection-in-avaya-web-license-manager/
More from Avaya
View All →Affected Vendor
Avaya
View all reports →