Avaya Communication Manager Web Server Configuration Unauthorized Access Vulnerability
BID:31639
Info
Avaya Communication Manager Web Server Configuration Unauthorized Access Vulnerability
| Bugtraq ID: | 31639 |
| Class: | Configuration Error |
| CVE: |
CVE-2008-5710 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | VoIPshield |
| Vulnerable: |
Avaya Communication Manager 4.0.3 SP1 Avaya Communication Manager 3.1.4 SP2 Avaya Communication Manager 5.1 Avaya Communication Manager 5.0 SP3 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 |
| Not Vulnerable: | |
Discussion
Avaya Communication Manager Web Server Configuration Unauthorized Access Vulnerability
Avaya Communication Manager is prone to an unauthorized-access vulnerability.
Attackers can exploit this issue to gain access to the application's configuration files, log files, binary image files, and help files. Successfully exploiting this issue may lead to further attacks.
Avaya Communication Manager is prone to an unauthorized-access vulnerability.
Attackers can exploit this issue to gain access to the application's configuration files, log files, binary image files, and help files. Successfully exploiting this issue may lead to further attacks.
Exploit / POC
Avaya Communication Manager Web Server Configuration Unauthorized Access Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Avaya Communication Manager Web Server Configuration Unauthorized Access Vulnerability
Solution:
A vendor advisory and update is available. Contact the vendor for details on obtaining the appropriate updates.
Solution:
A vendor advisory and update is available. Contact the vendor for details on obtaining the appropriate updates.
References
Avaya Communication Manager Web Server Configuration Unauthorized Access Vulnerability
References:
References:
- Avaya Communication Manager Unauthorized Web Access (VoIPshield)
- Avaya Homepage (Avaya Inc.)
- ASA-2008-394 Unauthenticated file access via CM web server (Avaya)