PT-2024-12872 · Atos · Atos Unify Openscape Voice Trace Manager

Published

2024-02-08

·

Updated

2025-12-30

·

CVE-2023-40262

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Atos Unify OpenScape Voice Trace Manager versions prior to V8 R0.9.11
Description An issue was discovered in the administration component of Atos Unify OpenScape Voice Trace Manager, allowing unauthenticated Stored Cross-Site Scripting (XSS) via Access Request. This issue affects the administration component and can be exploited without authentication.
Recommendations For versions prior to V8 R0.9.11, update to V8 R0.9.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the administration component to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-40262

Affected Products

Atos Unify Openscape Voice Trace Manager