CVE-2018-15616: Avaya Aura System Platform

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.

Affected products

  • Avaya Avaya Aura System Platform: from 6.3.0, up to and including 6.3.9; from 6.4.0, up to and including 6.4.2

Published 2018-10-17. Last modified 2026-06-17.