CVE-2018-15612

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
21/09/2018
Last modified:
09/10/2019

Description

A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avaya:orchestration_designer:*:*:*:*:*:*:*:* 7.2.1 (excluding)


References to Advisories, Solutions, and Tools