cvedb.io
CVE-2022-2975
HIGH · CVSS 7.7
EPSS exploitation probability: 0%
Published 2022-10-06T18:15:59.447 · Last modified 2026-06-17T04:42:54.800

Summary

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.

Affected products

avaya — aura_application_enablement_services

Does this affect you?

Add your gear to cvedb and we'll alert you only when avaya ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.