CVE-2018-15616: System Platform Web UI Deserialization
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Avaya Aura System Platform vulnerability?
The vulnerability ID for this Avaya Aura System Platform vulnerability is CVE-2018-15616.
What is the severity of CVE-2018-15616?
The severity of CVE-2018-15616 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2018-15616?
The affected software for CVE-2018-15616 is Avaya Aura System Platform versions 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
What is the description of CVE-2018-15616?
CVE-2018-15616 is a vulnerability in the Web UI component of Avaya Aura System Platform that could allow a remote, unauthenticated user to perform a targeted deserialization attack resulting in remote code execution.
How can I fix CVE-2018-15616?
To fix CVE-2018-15616, users should update their Avaya Aura System Platform to versions higher than 6.4.2.