// For flags

CVE-2008-6573

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.

Múltiples vulnerabilidades de inyección SQL en Avaya SIP Enablement Services (SES) en Avaya Avaya Communication Manager 3.x, 4.0, y 5.0 (1) permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores no especificados relacionados con perfiles en el SIP Personal Information Manager (SPIM) en la interfaz web; y permite a usuarios remotos autenticados ejecutar comandos SQL de su elección a través de vectores no especificados relacionados a (2) permisos para perfiles SPIM en la interfaz web y (3) una petición SIP manipulada en el servidor SIP.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-04-01 CVE Reserved
  • 2009-04-01 CVE Published
  • 2024-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
<= 3.1
Search vendor "Avaya" for product "Communication Manager" and version " <= 3.1"
-
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.1
Search vendor "Avaya" for product "Communication Manager" and version "3.1.1"
-
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.2
Search vendor "Avaya" for product "Communication Manager" and version "3.1.2"
-
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.3
Search vendor "Avaya" for product "Communication Manager" and version "3.1.3"
-
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.4
Search vendor "Avaya" for product "Communication Manager" and version "3.1.4"
-
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.4
Search vendor "Avaya" for product "Communication Manager" and version "3.1.4"
sp1
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.4
Search vendor "Avaya" for product "Communication Manager" and version "3.1.4"
sp2
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.5
Search vendor "Avaya" for product "Communication Manager" and version "3.1.5"
-
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
3.1.5
Search vendor "Avaya" for product "Communication Manager" and version "3.1.5"
sp0
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
4.0
Search vendor "Avaya" for product "Communication Manager" and version "4.0"
-
Affected
Avaya
Search vendor "Avaya"
Communication Manager
Search vendor "Avaya" for product "Communication Manager"
5.0
Search vendor "Avaya" for product "Communication Manager" and version "5.0"
-
Affected