Quantcast
Channel: Mitel MiContact Center Knowledge Base
Viewing all articles
Browse latest Browse all 959

Hotfix KB540487 - CCMWeb Path Traversal \ Arbitrary File Read Vulnerability Fix

$
0
0
Article ID: 52710 - Last Review: January 18, 2023

What’s Fixed?

This Hotfix resolves the following security issue detailed in CVE-2023-22854, and Security Advisory ID: 23-0001

Applicable Platform
(MiVB, Open SIP, Any)

Issue Description

Symptoms

Resolution

Any

CCMWeb has an endpoint (flexreport.ashx) which allowed for arbitrary file read of any file on the system

N/A

Added protection to disallow path traversal via the filename supplied which will prevent being able to read any arbitrary file on the system.

Cumulative Fixes Included

The following previous hotfixes are also included in this hotfix:

Hotfix

Description

Link

KB539258

Agent Group Performance by Agent report showing Agent Shift hours > 24 hours

Environment

MiContact Center Business

Installation

This Hotfix is to be installed onto MiContact Center Business version 9.4.1.0

  1. Go to https://www.mitel.com

  2. Click the Login button.

  3. Click the Sign in button under MiAccess.

  4. On the left, select the Software Download Center.

  5. Expand the tree to MiContact Center Business and then down to MiContact Center Business 9.4.1.0 and 9.4.1.0 HotFixes.

  6. Download the "MiCC Hotfix KB540487.exe" Hotfix to the MiContact Center server.

  7. Double-click the MiCC HotFix KB540487.exe and follow the on-screen prompts.

  8. Wait for the repackager and auto-updates to complete. 

NOTE: Applying this Hotfix will restart the MiContact Center services.  To avoid service interruption we recommend applying the update after hours or during a scheduled maintenance window.


Viewing all articles
Browse latest Browse all 959

Trending Articles