Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES)...
Vulnerability Description
Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-6573
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.voipshield.com/research-details.php?id=25
- http://www.voipshield.com/research-details.php?id=26
- http://www.voipshield.com/research-details.php?id=22
- http://support.avaya.com/elmodocs2/security/ASA-2008-151.htm
- http://osvdb.org/44286
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41733
- http://www.securityfocus.com/bid/28682
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41730
- http://osvdb.org/44284
- http://osvdb.org/44285
- http://support.avaya.com/elmodocs2/security/ASA-2008-150.htm
- http://secunia.com/advisories/29744
More from avaya
View All →Affected Vendor
avaya
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.