CVE-2022-2975

HIGH

Avaya Aura Application Enablement Ser... - Improper Privilege Management

Title source: rule
STIX 2.1

Description

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.

References (1)

Core 1

Scores

CVSS v3 7.7
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-269 CWE-732
Status published
Products (1)
avaya/aura_application_enablement_services 8.0.0.0 - 8.1.3.5
Published Oct 06, 2022
Tracked Since Feb 18, 2026