First published: Fri Apr 10 2009(Updated: )
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Aura SIP Enablement Services | =3.0 | |
Avaya Aura SIP Enablement Services | =3.1 | |
Avaya Aura SIP Enablement Services | =3.1.1 | |
Avaya Aura SIP Enablement Services | =4.0 | |
Avaya Communication Manager | =3.1 | |
Avaya Communication Manager | =3.1.1 | |
Avaya Communication Manager | =3.1.2 | |
Avaya Communication Manager | =3.1.3 | |
Avaya Communication Manager | =3.1.4 | |
Avaya Communication Manager | =3.1.4-sp1 | |
Avaya Communication Manager | =3.1.4-sp2 | |
Avaya Communication Manager | =3.1.5 | |
Avaya Communication Manager | =3.1.5-sp0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6707 has been rated as a critical severity vulnerability due to its potential for unauthorized access to sensitive information.
To mitigate CVE-2008-6707, apply the latest patches provided by Avaya for the affected versions of SIP Enablement Services and Communication Manager.
CVE-2008-6707 affects Avaya SIP Enablement Services 3.x and 4.0, along with Avaya Communication Manager versions 3.1 and several service packs.
CVE-2008-6707 can be exploited by remote attackers who can access the web management interface without proper authentication.
CVE-2008-6707 allows attackers to access sensitive information and restricted functionalities through the vulnerable web management interface.