Quantcast
Channel: Mitel MiContact Center Knowledge Base
Viewing all articles
Browse latest Browse all 959

Hotfix KB540484 - CCMWeb Path Traversal \ Arbitrary File Read Vulnerability Fix

$
0
0
Article ID:  - Last Review: January 18, 2023


What’s Fixed?

This Hotfix resolves the following security issue detailed in CVE-2023-22854, and Security Advisory ID: 23-0001

Applicable Platform
(MiVB, Open SIP, Any)

Issue Description

Symptoms

Resolution

Any

CCMWeb has an endpoint (flexreport.ashx) which allowed for arbitrary file read of any file on the system

N/A

Added protection to disallow path traversal via the filename supplied which will prevent being able to read any arbitrary file on the system.

Cumulative Fixes Included

The following previous hotfixes are also included in this hotfix:

Hotfix

Description

Link

KB539318

MiccSdk Slow Down - CPU Spike resulting in Web Ignite Disconnecting and Ignite users unable to see dashboard and queues

Release Notes

KB538335

Fixes for DTMF digits are missed or not being passed to PBX correctly

 Release Notes

KB537372

Fixes: Email Routing and Handling; Callback Dashboard \ Monitor; Backup Restore; IVR Excel Data Provider

Release Notes

KB536902

Fixes: Unable to save employee added via Pick user from Active directory and Email processing fixes and improvements

Release Notes

KB536401

Fixes for Microsoft Exchange OAuth mail server connections and Web Ignite Callback Widget issue

Release Notes


Environment

MiContact Center Business

Installation

This Hotfix is to be installed onto MiContact Center Business version 9.4.0.0

  1. Go to https://www.mitel.com

  2. Click the Login button.

  3. Click the Sign in button under MiAccess.

  4. On the left, select the Software Download Center.

  5. Expand the tree to MiContact Center Business and then down to MiContact Center Business 9.4.0.0 and 9.4.0.0 HotFixes.

  6. Download the "MiCC Hotfix KB540484.exe" Hotfix to the MiContact Center server.

  7. Double-click the MiCC HotFix KB540484.exe and follow the on-screen prompts.

  8. Wait for the repackager and auto-updates to complete. 

NOTE: Applying this Hotfix will restart the MiContact Center services.  To avoid service interruption we recommend applying the update after hours or during a scheduled maintenance window.


Viewing all articles
Browse latest Browse all 959

Trending Articles