|
Avaya SES Authentication Bypass Vulnerability and Information Disclosure Weakness
Avaya SES (SIP Enablement Services) server is prone to an authentication-bypass vulnerability because it fails to adequately protect administrative areas within the application. The information-disclosure weakness is caused by the application writing sensitive information to logs. Attackers can exploit the authentication-bypass issue to render the server unusable for a period. Exploiting the information-disclosure weakness may give the attacker unauthorized access to login credentials. Avaya SES 5.0 and CM 5.0 on S8300C with SES enabled are vulnerable; other versions may also be affected. |
|
|
Privacy Statement |