CVE-2008-6707: Medium severity avaya aura sip enablement services vulnerability
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6707?
CVE-2008-6707 has been rated as a critical severity vulnerability due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2008-6707?
To mitigate CVE-2008-6707, apply the latest patches provided by Avaya for the affected versions of SIP Enablement Services and Communication Manager.
What are the affected versions of software by CVE-2008-6707?
CVE-2008-6707 affects Avaya SIP Enablement Services 3.x and 4.0, along with Avaya Communication Manager versions 3.1 and several service packs.
What type of attackers can exploit CVE-2008-6707?
CVE-2008-6707 can be exploited by remote attackers who can access the web management interface without proper authentication.
What kind of information can be accessed due to CVE-2008-6707?
CVE-2008-6707 allows attackers to access sensitive information and restricted functionalities through the vulnerable web management interface.