CVE-2018-15616

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
References
Link Resource
https://downloads.avaya.com/css/P8/documents/101052865 Exploit Vendor Advisory
Configurations

Configuration 1

cpe:2.3:h:avaya:avaya_aura_system_platform:*:*:*:*:*:*:*:*
cpe:2.3:h:avaya:avaya_aura_system_platform:*:*:*:*:*:*:*:*

Information

Published : 2018-10-17 06:29

Updated : 2019-10-09 11:35


NVD link : CVE-2018-15616

Mitre link : CVE-2018-15616

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data