CVE-2018-15616

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
References
Link Resource
https://downloads.avaya.com/css/P8/documents/101052865 Exploit Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:avaya:avaya_aura_system_platform:*:*:*:*:*:*:*:*
cpe:2.3:h:avaya:avaya_aura_system_platform:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-10-17 18:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-15616

Mitre link : CVE-2018-15616

CVE.ORG link : CVE-2018-15616


JSON object : View

Products Affected

avaya

  • avaya_aura_system_platform
CWE
CWE-502

Deserialization of Untrusted Data