CVE-2019-7003 CRITICAL

CVE-2019-7003: ACM SQL Injection

Vendor Avaya
Product Avaya Control Manager
Weakness CWE-89 · SQLi
Published July 11, 2019
Last update September 17, 2024

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

What the vulnerability does

01Description

A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.

Key dates

02Disclosure timeline

July 11, 2019 CVE published
September 17, 2024 Record updated