Show filters
137 Total Results
Displaying 1-10 of 137
Sort by:
Attacker Value
Unknown
CVE-2024-4196
Disclosure Date: June 25, 2024 (last updated January 22, 2025)
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.
1
Attacker Value
Unknown
CVE-2024-12756
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.
0
Attacker Value
Unknown
CVE-2024-12755
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.
0
Attacker Value
Unknown
CVE-2024-7480
Disclosure Date: August 08, 2024 (last updated September 12, 2024)
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
0
Attacker Value
Unknown
CVE-2024-7477
Disclosure Date: August 08, 2024 (last updated September 12, 2024)
A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.
Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
0
Attacker Value
Unknown
CVE-2024-4197
Disclosure Date: June 25, 2024 (last updated January 22, 2025)
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.
0
Attacker Value
Unknown
CVE-2023-7031
Disclosure Date: January 17, 2024 (last updated January 26, 2024)
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 patch 0402. Versions prior to 8.0 are end of manufacturer support.
0
Attacker Value
Unknown
CVE-2023-3722
Disclosure Date: July 19, 2023 (last updated October 08, 2023)
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
0
Attacker Value
Unknown
CVE-2023-3527
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software
such as Microsoft Excel.
0
Attacker Value
Unknown
CVE-2023-31187
Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
0