PT-2008-6762 · Avaya · Avaya Communication Manager
Published
2008-12-24
·
Updated
2017-08-08
·
CVE-2008-5710
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Avaya Communication Manager versions 3.1.x through 5.x
Avaya Communication Manager version 4.0.3
Description
The issue affects the web management interface, allowing remote attackers to read sensitive files, including configuration files, log files, binary image files, and help files, via unknown vectors.
Recommendations
For Avaya Communication Manager versions 3.1.x through 5.x, update to a version that addresses the issue.
For Avaya Communication Manager version 4.0.3, update to a version that addresses the issue.
As a temporary workaround, consider restricting access to the web management interface to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avaya Communication Manager