First published: Wed Oct 17 2018(Updated: )
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
Credit: securityalerts@avaya.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Avaya Aura System Platform | >=6.3.0<=6.3.9 | |
Avaya Avaya Aura System Platform | >=6.4.0<=6.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Avaya Aura System Platform vulnerability is CVE-2018-15616.
The severity of CVE-2018-15616 is critical with a CVSS score of 9.8.
The affected software for CVE-2018-15616 is Avaya Aura System Platform versions 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
CVE-2018-15616 is a vulnerability in the Web UI component of Avaya Aura System Platform that could allow a remote, unauthenticated user to perform a targeted deserialization attack resulting in remote code execution.
To fix CVE-2018-15616, users should update their Avaya Aura System Platform to versions higher than 6.4.2.