Show filters
137 Total Results
Displaying 11-20 of 137
Sort by:
Attacker Value
Unknown

CVE-2023-31186

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
Attacker Value
Unknown

CVE-2023-32218

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Attacker Value
Unknown

CVE-2022-38168

Disclosure Date: November 03, 2022 (last updated November 08, 2023)
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Attacker Value
Unknown

CVE-2022-2249

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.
Attacker Value
Unknown

CVE-2022-2975

Disclosure Date: October 06, 2022 (last updated October 08, 2023)
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.
Attacker Value
Unknown

CVE-2021-25657

Disclosure Date: September 02, 2022 (last updated October 08, 2023)
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.
Attacker Value
Unknown

CVE-2021-25654

Disclosure Date: June 25, 2021 (last updated November 28, 2024)
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
Attacker Value
Unknown

CVE-2021-25655

Disclosure Date: June 24, 2021 (last updated November 28, 2024)
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
Attacker Value
Unknown

CVE-2021-25656

Disclosure Date: June 24, 2021 (last updated November 28, 2024)
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
Attacker Value
Unknown

CVE-2021-25650

Disclosure Date: June 24, 2021 (last updated November 08, 2023)
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services