Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Avaya SES Authentication Bypass Vulnerability and Information Disclosure Weakness

Avaya SES (SIP Enablement Services) server is prone to an authentication-bypass vulnerability because it fails to adequately protect administrative areas within the application. The information-disclosure weakness is caused by the application writing sensitive information to logs.

Attackers can exploit the authentication-bypass issue to render the server unusable for a period. Exploiting the information-disclosure weakness may give the attacker unauthorized access to login credentials.

Avaya SES 5.0 and CM 5.0 on S8300C with SES enabled are vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus