Back

CVE-2019-7003

CRITICAL

A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.

Published: Jul 11, 2019 Modified: Jun 17, 2026
CWE-89 CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Affected Products (1)

Vendor Product Version
avaya control_manager * ≥ 7.0 < 8.0.4.0

GitHub Security Advisory GHSA-j7fq-gw6j-cr4j

A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 1.46%

Top 29% most likely to be exploited

Threat Score 40.4 / 100

Data Sources

NVD EPSS GitHub