Release Date: 2008-10-14
Critical:
Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Unpatched
OS: Avaya Message Networking 2.x
Avaya Modular Messaging 2.x
Avaya Modular Messaging 3.x
Avaya SIP Enablement Services (SES) 3.x
Software: Avaya Application Enablement Services 3.x
Avaya Application Enablement Services 4.x
Avaya Communication Manager 3.x
Description:
Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.
Solution:
The vendor recommends that local and network access to the affected systems be restricted until an update is available.
Original Advisory:
http://support.avaya.com/elmodocs2/security/ASA-2008-400.htm
Other References:
SA31558:
http://secunia.com/advisories/31558/
Avaya AES / MX Apache Tomcat Multiple Vulnerabilities
Release Date: 2008-10-14
Critical:
Moderately critical
Impact: Security Bypass
Cross Site Scripting
Exposure of system information
Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
Software: Avaya Application Enablement Services 3.x
Avaya Application Enablement Services 4.x
Description:
Avaya has acknowledged some vulnerabilities in Avaya AES / MX, which can be exploited by malicious, local users to bypass certain security restrictions, by malicious users to disclose potentially sensitive information, and by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or disclose sensitive information.
Solution:
The vendor recommends that local and network access to the affected systems be restricted until an update is available.
Original Advisory:
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm
Other References:
SA27398:
http://secunia.com/advisories/27398/
SA28274:
http://secunia.com/advisories/28274/
SA30500:
http://secunia.com/advisories/30500/
SA31379:
http://secunia.com/advisories/31379/

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic