PT-2008-6761 · Avaya · Avaya Communication Manager

Publicado

2008-12-24

·

Atualizado

2017-08-08

·

CVE-2008-5709

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Avaya Communication Manager versions 3.1 through 3.1.4 SP1 Avaya Communication Manager versions 4.0 through 4.0.3 Avaya Communication Manager versions 5.0 through 5.0 SP2
Description The issue affects the web management interface, allowing remote authenticated users to execute arbitrary code. This is possible through unknown attack vectors in the Set Static Routes and Backup History components.
Recommendations For Avaya Communication Manager versions 3.1 through 3.1.4 SP1, update to version 3.1.4 SP2. For Avaya Communication Manager versions 4.0 through 4.0.3, update to version 4.0.3 SP1. For Avaya Communication Manager versions 5.0 through 5.0 SP2, update to version 5.0 SP3.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5709

Produtos afetados

Avaya Communication Manager