CVE-2008-6573
Estado: ModificadaMedia (6.8)—
Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.50%
- Percentil entre todas las CVEs puntuadas: 73
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
- http://osvdb.org/44284
- http://osvdb.org/44285
- http://osvdb.org/44286
- http://secunia.com/advisories/29744
- http://support.avaya.com/elmodocs2/security/ASA-2008-150.htm
- http://support.avaya.com/elmodocs2/security/ASA-2008-151.htm
- http://www.securityfocus.com/bid/28682
- http://www.voipshield.com/research-details.php?id=22
- http://www.voipshield.com/research-details.php?id=25
- http://www.voipshield.com/research-details.php?id=26
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41730
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41733
- http://osvdb.org/44284
- http://osvdb.org/44285
- http://osvdb.org/44286
- http://secunia.com/advisories/29744
- http://support.avaya.com/elmodocs2/security/ASA-2008-150.htm
- http://support.avaya.com/elmodocs2/security/ASA-2008-151.htm
- http://www.securityfocus.com/bid/28682
- http://www.voipshield.com/research-details.php?id=22
- http://www.voipshield.com/research-details.php?id=25
- http://www.voipshield.com/research-details.php?id=26
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41730
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41733
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-6573",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-04-01T22:30:00.187",
"references": [
{
"url": "http://osvdb.org/44284",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/44285",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/44286",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29744",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-150.htm",
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-151.htm",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28682",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=22",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=25",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=26",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41730",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41733",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/44284",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/44285",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/44286",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29744",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-150.htm",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-151.htm",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/28682",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=22",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=25",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=26",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41730",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41733",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de inyección SQL en Avaya SIP Enablement Services (SES) en Avaya Avaya Communication Manager 3.x, 4.0, y 5.0 (1) permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores no especificados relacionados con perfiles en el SIP Personal Information Manager (SPIM) en la interfaz web; y permite a usuarios remotos autenticados ejecutar comandos SQL de su elección a través de vectores no especificados relacionados a (2) permisos para perfiles SPIM en la interfaz web y (3) una petición SIP manipulada en el servidor SIP."
}
],
"lastModified": "2026-06-16T23:02:29.923",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:avaya:communication_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B13FEC26-15CC-4F82-8C24-BBD9C3FBA80E",
"versionEndIncluding": "3.1"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4030E5D-BC15-481D-A15E-98FAE65130D9"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3FC3A86-CE3D-4C12-9E31-7F7280EF9D28"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBD119B9-FE11-4165-943D-119E906DC013"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89F99C5C-C184-4A5C-B8BA-F558C4A38730"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.4:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EAA2BC9-4794-4441-8AA8-3C1B7297FD06"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.4:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "423E4EEB-3D6F-449E-B623-C8D051E8FA3B"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87089C0E-2241-46A7-93EE-EC41D52A89C6"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.5:sp0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BD89D61-0B42-4DDE-99F1-71570A37A136"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F0B0D66-9900-4B9A-A892-31B8607DA852"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84E2136B-6FE3-4548-A89D-444ED9393C22"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}