CVE-2024-7477: Avaya Aura System Manager SQL injection vulnerability
A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.
Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7477?
CVE-2024-7477 has a high severity rating due to its potential to allow unauthorized command execution in the Avaya Aura System Manager database by users with administrative privileges.
How do I fix CVE-2024-7477?
To fix CVE-2024-7477, upgrade the Avaya Aura System Manager to a patched version that is not vulnerable, specifically one beyond version 10.2.
Which versions are affected by CVE-2024-7477?
CVE-2024-7477 affects the Avaya Aura System Manager versions 10.1.x.x and 10.2.x.x.
Can CVE-2024-7477 be exploited remotely?
CVE-2024-7477 requires administrative access, so it cannot be exploited remotely by unauthorized users.
Are there any mitigations for CVE-2024-7477 if immediate patching is not possible?
If immediate patching is not possible for CVE-2024-7477, limit administrative access and monitor database logs for unusual query activity.