AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-7003

CRITICAL · CVSS 10 EPSS 1.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-07-11 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 10.0. It involves a SQL injection risk. Exploitation may require the attacker to be authenticated.

CVE
CVE-2019-7003
Severity
CRITICAL
CVSS
10
EPSS
1.46%

Original NVD Description

A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.

Related CVEs

Other vulnerabilities affecting the same vendor(s)