Back

HIGH

XXE in Avaya Aura Orchestration Designer

Published Apr 23, 2021

Description

An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner avaya
Published Apr 23, 2021
Updated Sep 16, 2024
Reserved Jan 14, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner avaya
Published Apr 23, 2021
Updated Sep 16, 2024
Exploited since n/a
EUVD-2020-28169