Show filters
137 Total Results
Displaying 41-50 of 137
Sort by:
Attacker Value
Unknown
Avaya one-X Communicator Weak Encryption
Disclosure Date: February 27, 2019 (last updated November 27, 2024)
Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13.
0
Attacker Value
Unknown
Communication Manager Denial of Service
Disclosure Date: February 01, 2019 (last updated November 27, 2024)
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
0
Attacker Value
Unknown
IP Office one-X Portal XSS
Disclosure Date: January 23, 2019 (last updated November 27, 2024)
A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1.
0
Attacker Value
Unknown
System Platform Web UI Deserialization
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
0
Attacker Value
Unknown
Communication Manager Local Administrator PrivEsc
Disclosure Date: September 27, 2018 (last updated November 27, 2024)
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
0
Attacker Value
Unknown
CMS Supervisor Information Disclosure
Disclosure Date: September 24, 2018 (last updated November 27, 2024)
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
0
Attacker Value
Unknown
Orchestration Designer Runtime Config CSRF
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0
Attacker Value
Unknown
Orchestration Designer Runtime Config XSS
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0
Attacker Value
Unknown
Improper access controls in IP Office one-X Portal
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.
0
Attacker Value
Unknown
CVE-2018-6635
Disclosure Date: February 05, 2018 (last updated November 26, 2024)
System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (RMI) restrictions, aka SMGR-26896.
0