Avaya SIP Enablement Services (SES) Server Multiple Input Validation Vulnerabilities
BID:28687
Info
Avaya SIP Enablement Services (SES) Server Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28687 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6574 CVE-2008-6575 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | VoIPshield Systems Inc |
| Vulnerable: |
Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 |
| Not Vulnerable: |
Avaya Aura SIP Enablement Services 5.1 |
Discussion
Avaya SIP Enablement Services (SES) Server Multiple Input Validation Vulnerabilities
Avaya SIP Enablement Services (SES) is prone to multiple input-validation vulnerabilities, including two SQL-injection issues and an authentication-bypass issue.
Attackers can exploit these issues to execute arbitrary SQL commands, cause denial-of-service conditions, or elevate privileges.
Avaya SIP Enablement Services (SES) is prone to multiple input-validation vulnerabilities, including two SQL-injection issues and an authentication-bypass issue.
Attackers can exploit these issues to execute arbitrary SQL commands, cause denial-of-service conditions, or elevate privileges.
Exploit / POC
Avaya SIP Enablement Services (SES) Server Multiple Input Validation Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Avaya SIP Enablement Services (SES) Server Multiple Input Validation Vulnerabilities
Solution:
Updates are available to address these issues. Please see the references for more information.
Solution:
Updates are available to address these issues. Please see the references for more information.
References
Avaya SIP Enablement Services (SES) Server Multiple Input Validation Vulnerabilities
References:
References:
- ASA-2008-150 Input Validation Vulnerabilities in Avaya SES SIP Server (Avaya)
- SES SIP Credential Reuse (VoIPshield Systems Inc)
- SES SIP SQL Denial of Service (VoIPshield Systems Inc)
- SES SIP SQL Injection (VoIPshield Systems Inc)