CVE-2018-15612: Orchestration Designer Runtime Config CSRF
Published Sep 21, 2018
·Updated
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
Affected Software
1 affected component
Avaya Orchestration Designer<7.2.1
Remediation
Patch Available
Event History
Sep 21, 2018
CVE Published
05:29 PM
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Avaya Aura Orchestration Designer vulnerability?
The vulnerability ID for this Avaya Aura Orchestration Designer vulnerability is CVE-2018-15612.
2
What is the severity of CVE-2018-15612?
The severity of CVE-2018-15612 is high with a CVSS score of 8.8.
3
What is the affected software of CVE-2018-15612?
The affected software of CVE-2018-15612 is Avaya Orchestration Designer up to version 7.2.1.
4
What is the impact of CVE-2018-15612?
CVE-2018-15612 allows an attacker to add, change, or remove administrative settings.
5
Is there a fix available for CVE-2018-15612?
Yes, a fix is available for CVE-2018-15612. It is recommended to update to a version of Avaya Orchestration Designer that is not affected by the vulnerability.