← Back

CVE-2020-7036

nvd nist
Published: Apr 23, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.

Affected (8)

1 product
Callback Assist
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Avaya
From 4.0.0 to 4.7.1.1
Version 4.7.1.1
Version 4.7.1.1 patch1
Version 4.7.1.1 patch2
Version 4.7.1.1 patch3
Version 4.7.1.1 patch4
Version 4.7.1.1 patch5
Version 4.7.1.1 patch6

References (2)

Source: securityalerts@avaya.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.