Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
18.0 (custom) before 19.2.0.7
affected
20.0 (custom) before 20.0.1.0
affected
Description
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
Problem types
CWE-20 Improper Input Validation
Product status
18.0 (custom) before 19.2.0.7
20.0 (custom) before 20.0.1.0
Credits
Roberto Olivero
Juan Ignacio Elola
References
support.avaya.com/css/public/documents/101093084