An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Aura_system_manager | Avaya | 10.1 (including) | 10.1.2 (including) | 
| Aura_system_manager | Avaya | 10.2 (including) | 10.2 (including) |