Description: Some vulnerabilities have been reported in Avaya Message Storage Server, which can be exploited by malicious users to compromise a vulnerable system.
Multiple input validation errors in the web management interface can be exploited to execute arbitrary code on an affected system.
Successful exploitation requires valid user credentials to the web management interface.
The vulnerabilities are reported in version 3.x and 4.0.
Solution: The vendor recommends that local and network access to the affected systems be restricted until an update is available.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.