Show filters
461 Total Results
Displaying 211-220 of 461
Sort by:
Attacker Value
Unknown

Communication Manager Denial of Service

Disclosure Date: February 01, 2019 (last updated November 27, 2024)
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
0
Attacker Value
Unknown

IP Office one-X Portal XSS

Disclosure Date: January 23, 2019 (last updated November 27, 2024)
A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.
0
Attacker Value
Unknown

CVE-2019-5312

Disclosure Date: January 04, 2019 (last updated November 27, 2024)
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
0
Attacker Value
Unknown

CVE-2018-20318

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
0
Attacker Value
Unknown

CVE-2018-12076

Disclosure Date: December 13, 2018 (last updated February 15, 2024)
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Disclosure. The vulnerability is due to lack of proper validation of the UPC bar code present on the MarketCard. An attacker could exploit this vulnerability by generating a copy of a customer's bar code. An exploit could allow the attacker to access all funds located within the MarketCard or allow unauthenticated disclosure of information.
0
Attacker Value
Unknown

System Platform Web UI Deserialization

Disclosure Date: October 17, 2018 (last updated November 27, 2024)
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
0
Attacker Value
Unknown

Communication Manager Local Administrator PrivEsc

Disclosure Date: September 27, 2018 (last updated November 27, 2024)
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
0
Attacker Value
Unknown

CVE-2018-15531

Disclosure Date: September 26, 2018 (last updated November 27, 2024)
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
0
Attacker Value
Unknown

CMS Supervisor Information Disclosure

Disclosure Date: September 24, 2018 (last updated November 27, 2024)
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
0
Attacker Value
Unknown

Orchestration Designer Runtime Config CSRF

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0