Avaya
avaya
139 CVEs • 158 products
Products (158)
Click to collapseToggle
Products (158)
Click to collapse
CVEs (139)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Avaya 1Aura Experience Portal Nov 21, 2024 Jun 24, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix)...Show more |
1Avaya 1Aura Appliance Virtualization Platform Nov 21, 2024 Jun 24, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 version...Show more |
1Avaya 1Aura Appliance Virtualization Platform Nov 21, 2024 Jun 24, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to acc...Show more |
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services |
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura...Show more |
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and confi...Show more |
A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected...Show more |
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system o...Show more |
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assi...Show more |
1Avaya 1Aura Orchestration Designer Nov 21, 2024 Apr 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affec...Show more |
1Avaya 1Session Border Controller For Enterprise Nov 21, 2024 Apr 23, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system...Show more |
1Avaya 2Aura System Manager WeblmNov 21, 2024 Nov 13, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affe...Show more |
A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks. The affected versions of Equinox Conferencin...Show more |
1Avaya 2Aura Communication Manager Aura MessagingNov 21, 2024 Aug 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenti...Show more |
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office inclu...Show more |
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Of...Show more |
A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are...Show more |
1Avaya 1Ip Office Application Server Nov 21, 2024 Dec 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affe...Show more |
5Avaya DebianMozilla+2 more27Aura Application Enablement Services Aura Application Server 5300Aura Communication Manager+24 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more |
A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x ve...Show more |