CVE-2018-15616

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:avaya:avaya_aura_system_platform:*:*:*:*:*:*:*:*
cpe:2.3:h:avaya:avaya_aura_system_platform:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:51

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 9.0
References () https://downloads.avaya.com/css/P8/documents/101052865 - Exploit, Vendor Advisory () https://downloads.avaya.com/css/P8/documents/101052865 - Exploit, Vendor Advisory

Information

Published : 2018-10-17 18:29

Updated : 2024-11-21 03:51


NVD link : CVE-2018-15616

Mitre link : CVE-2018-15616

CVE.ORG link : CVE-2018-15616


JSON object : View

Products Affected

avaya

  • avaya_aura_system_platform
CWE
CWE-502

Deserialization of Untrusted Data