Medium severity6.5NVD Advisory· Published Nov 13, 2020· Updated Jun 17, 2026
CVE-2020-7032
CVE-2020-7032
Description
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:avaya:aura_system_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:avaya:aura_system_manager:*:*:*:*:*:*:*:*range: >=7.0,<=7.1.3.6
- (no CPE)range: 8.0.x
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/160123/Avaya-Web-License-Manager-XML-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2020/Nov/31nvdExploitMailing ListThird Party Advisory
- sec-consult.com/vulnerability-lab/advisory/blind-out-of-band-xml-external-entity-injection-in-avaya-web-license-manager/nvdExploitThird Party Advisory
- downloads.avaya.com/css/P8/documents/101072249nvdVendor Advisory
News mentions
0No linked articles in our index yet.