A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.  Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
History

Wed, 11 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:avaya:aura_system_manager:10.2:*:*:*:*:*:*:*

Fri, 09 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Avaya
Avaya aura System Manager
CPEs cpe:2.3:a:avaya:aura_system_manager:*:*:*:*:*:*:*:*
Vendors & Products Avaya
Avaya aura System Manager
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 16:15:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.  Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
Title Avaya Aura System Manager SQL injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: avaya

Published: 2024-08-08T16:02:43.125Z

Updated: 2024-08-09T18:21:58.052Z

Reserved: 2024-08-05T07:37:13.538Z

Link: CVE-2024-7477

cve-icon Vulnrichment

Updated: 2024-08-09T18:21:53.406Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-08T16:15:09.363

Modified: 2024-09-11T15:03:06.637

Link: CVE-2024-7477

cve-icon Redhat

No data.