Back
CVE-2019-7003
CRITICAL
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.
Published: Jul 11, 2019
Modified: Jun 17, 2026
CWE-89
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| avaya | control_manager | * ≥ 7.0 < 8.0.4.0 |
GitHub Security Advisory GHSA-j7fq-gw6j-cr4j
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an...
References (5)
- http://www.securityfocus.com/bid/109134 Broken Link, Third Party Advisory, VDB Entry
- https://downloads.avaya.com/css/P8/documents/101059368 Vendor Advisory
- https://support.avaya.com/documents/documents-by-contenttype.action?product_id=P0941&product_name=Control+Manager&release_number=releaseId&contentType=ReleaseNotes Release Notes, Vendor Advisory
- http://www.securityfocus.com/bid/109134 Broken Link, Third Party Advisory, VDB Entry
- https://downloads.avaya.com/css/P8/documents/101059368 Vendor Advisory
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
1.46%
Top 29% most likely to be exploited
Threat Score
40.4 / 100
Data Sources
NVD
EPSS
GitHub