CVE-2018-15610: Improper access controls in IP Office one-X Portal
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15610?
CVE-2018-15610 is a vulnerability in the one-X Portal component of Avaya IP Office that allows an authenticated attacker to read and delete arbitrary files on the system.
Which versions of Avaya IP Office are affected by CVE-2018-15610?
Versions 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2 of Avaya IP Office are affected by CVE-2018-15610.
What is the severity of CVE-2018-15610?
CVE-2018-15610 has a severity rating of 8.8 (Critical).
How can the CVE-2018-15610 vulnerability be fixed?
To fix the CVE-2018-15610 vulnerability, it is recommended to upgrade to a patched version of Avaya IP Office.
Where can I find more information about CVE-2018-15610?
More information about CVE-2018-15610 can be found at the following references: [link1](https://downloads.avaya.com/css/P8/documents/101051984), [link2](https://packetstormsecurity.com/files/149284/Avaya-one-X-9.x-10.0.x-10.1.x-Arbitrary-File-Disclosure-Deletion.html).