Quantcast
Channel: Mitel MiContact Center Knowledge Base
Viewing all articles
Browse latest Browse all 959

Hotfix KB540438 CCMWeb Path Traversal \ Arbitrary File Read Vulnerability Fix

$
0
0
Article ID: 52708 - Last Review: January 18, 2023

What’s Fixed?

This Hotfix resolves the following security issue detailed in CVE-2023-22854, and Security Advisory ID: 23-0001

Applicable Platform
(MiVB, Open SIP, Any)

Issue Description

Symptoms

Resolution

Any

CCMWeb has an endpoint (flexreport.ashx) which allowed for arbitrary file read of any file on the system

N/A

Added protection to disallow path traversal via the filename supplied which will prevent being able to read any arbitrary file on the system.

Cumulative Fixes Included

The following previous hotfixes are also included in this hotfix:

Hotfix

Description

Link

KB539475

Fixes multiple SIP Call Scenarios issues, RoutingMediaService unable to process commands, Ignite focus issues, callback display issues and configuration changes issue

KB530024

  • This Hotfix addresses two problems occurring during PCI compliance:

    • If the caller hangs up while the agent is on hold, the agent and IVR port call are not cleared.

    • When the caller is done entering the information required and the agent re-joins the conference, the PCI compliance workflow doesn't move on to the next activity until after 10 seconds. 

Release Notes

Environment

MiContact Center Business

Installation

This Hotfix is to be installed onto MiContact Center Business version 9.3.5.0

  1. Go to https://www.mitel.com

  2. Click the Login button.

  3. Click the Sign in button under MiAccess.

  4. On the left, select the Software Download Center.

  5. Expand the tree to MiContact Center Business and then down to MiContact Center Business 9.3.5.0 and 9.3.5.0 HotFixes.

  6. Download the "MiCC Hotfix KB540438.exe" Hotfix to the MiContact Center server.

  7. Double-click the MiCC HotFix KB540438.exe and follow the on-screen prompts.

  8. Wait for the repackager and auto-updates to complete. 

NOTE: Applying this Hotfix will restart the MiContact Center services.  To avoid service interruption we recommend applying the update after hours or during a scheduled maintenance window.


Viewing all articles
Browse latest Browse all 959

Trending Articles