CVE-2018-15613
Summary
| CVE | CVE-2018-15613 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-21 17:29:00 UTC |
| Updated | 2019-10-09 23:35:00 UTC |
| Description | A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Avaya | Aura Orchestration Designer | All | All | All | All |
| Application | Avaya | Aura Orchestration Designer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ASA-2018-278 (CVE-2018-15612, CVE-2018-15613) | CONFIRM | downloads.avaya.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.