Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Avaya Call Management System (CMS)
This vulnerability report for Avaya Call Management System (CMS) contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Avaya Call Management System (CMS) then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Avaya

Product Link View Here (Link to external site)

Affected By 99 Secunia advisories
141 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 63% (62 of 99 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Avaya Call Management System (CMS), with all vendor patches applied, is rated Highly critical .




22 Secunia Advisories in 2007
Secunia has issued a total of 22 Secunia advisories in 2007 for Avaya Call Management System (CMS). Currently, 36% (8 out of 22) are marked as unpatched with the most severe being rated Moderately critical

More information about the specific Secunia advisories affecting Avaya Call Management System (CMS) can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Avaya CMS / IR Solaris Remote Procedure Call Module Denial of Service
Partial Fix. Secunia Advisory 1 of 22 in 2007. 5,115 views.
Release Date:
2007-12-12
Secunia Advisory ID:
SA28057
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR Sun Solaris FIFO File System Unauthorized Data Access
Vendor Patch. Secunia Advisory 2 of 22 in 2007. 5,291 views.
Release Date:
2007-11-13
Secunia Advisory ID:
SA27654
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users to disclose potentially sensitive information. [Read More]


Avaya CMS / IR Sun Solaris Kernel Statistics Retrieval Denial of Service
Partial Fix. Secunia Advisory 3 of 22 in 2007. 5,644 views.
Release Date:
2007-11-05
Secunia Advisory ID:
SA27536
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Avaya has acknowledged some vulnerabilities in Avaya CMS and IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR BIND Predictable DNS Query IDs Vulnerability
Unpatched. Secunia Advisory 4 of 22 in 2007. 5,656 views.
Release Date:
2007-10-31
Secunia Advisory ID:
SA27459
Solution Status:
Unpatched
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious people to poison the DNS cache. [Read More]


Avaya CMS / IR Sun Solaris RPC Services Library Denial of Service
Partial Fix. Secunia Advisory 5 of 22 in 2007. 5,399 views.
Release Date:
2007-10-25
Secunia Advisory ID:
SA27386
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users and malicious users to cause a DoS (Denial of Service). [Read More]


Avaya CMS Solaris Human Interface Device Denial of Service
Unpatched. Secunia Advisory 6 of 22 in 2007. 5,536 views.
Release Date:
2007-10-03
Secunia Advisory ID:
SA27019
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR Solaris Thread Context Handling Denial of Service
Partial Fix. Secunia Advisory 7 of 22 in 2007. 5,795 views.
Release Date:
2007-10-03
Secunia Advisory ID:
SA27059
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR Solaris Special File System "strfreectty()" Security Issue
Unpatched. Secunia Advisory 8 of 22 in 2007. 7,427 views.
Release Date:
2007-09-07
Secunia Advisory ID:
SA26731
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Avaya has acknowledged a security issue in Avaya CMS and IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR Solaris lbxproxy Privilege Escalation Vulnerability
Partial Fix. Secunia Advisory 9 of 22 in 2007. 6,552 views.
Release Date:
2007-08-07
Secunia Advisory ID:
SA26344
Solution Status:
Partial Fix
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
Privilege escalation
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious, local users to perform certain actions with escalated privileges. [Read More]


Avaya CMS / IR Solaris rcp Command Line Shell Command Injection
Vendor Patch. Secunia Advisory 10 of 22 in 2007. 16,910 views.
Release Date:
2007-07-25
Secunia Advisory ID:
SA26210
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Avaya has acknowledged a weakness in Avaya CMS / IR, which can be exploited by malicious, local users to perform certain actions with escalated privileges. [Read More]


Avaya CMS / IR libsldap Denial of Service
Partial Fix. Secunia Advisory 11 of 22 in 2007. 7,655 views.
Release Date:
2007-07-20
Secunia Advisory ID:
SA26125
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Avaya has acknowledged a weakness in Avaya CMS and IR, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR Solaris dtsession Privilege Escalation Vulnerability
Partial Fix. Secunia Advisory 12 of 22 in 2007. 6,890 views.
Release Date:
2007-07-20
Secunia Advisory ID:
SA26136
Solution Status:
Partial Fix
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Avaya CMS / IR Solaris scp Command Line Shell Command Injection
Unpatched. Secunia Advisory 13 of 22 in 2007. 7,477 views.
Release Date:
2007-07-04
Secunia Advisory ID:
SA25936
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Avaya has acknowledged a weakness in Avaya CMS and IR, which can be exploited by malicious, local users to perform certain actions with escalated privileges. [Read More]


Avaya CMS / IR Sun Solaris NFS Client Module Denial of Service
Vendor Patch. Secunia Advisory 14 of 22 in 2007. 5,044 views.
Release Date:
2007-06-28
Secunia Advisory ID:
SA25879
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Avaya CMS Sun Solaris "in.iked" Denial of Service Vulnerability
Unpatched. Secunia Advisory 15 of 22 in 2007. 4,583 views.
Release Date:
2007-06-14
Secunia Advisory ID:
SA25661
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS (Call Management System), which can be exploited by malicious users to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR X.Org X11 Multiple Vulnerabilities
Unpatched. Secunia Advisory 16 of 22 in 2007. 6,587 views.
Release Date:
2007-05-10
Secunia Advisory ID:
SA25216
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of sensitive information
Privilege escalation
DoS
Where:
Local system
Short Description:
Avaya has acknowledged some vulnerabilities in Avaya CMS and IR, which can be exploited by malicious, local users to disclose sensitive information, cause a DoS (Denial of Service), and gain escalated privileges. [Read More]


Avaya CMS / IR Sun Solaris libX11 Integer Overflow Vulnerability
Unpatched. Secunia Advisory 17 of 22 in 2007. 5,382 views.
Release Date:
2007-05-03
Secunia Advisory ID:
SA25112
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Avaya CMS / IR Sun Solaris IP Packet Denial of Service
Partial Fix. Secunia Advisory 18 of 22 in 2007. 5,307 views.
Release Date:
2007-04-23
Secunia Advisory ID:
SA24987
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR Sun Solaris rm Race Condition Vulnerability
Partial Fix. Secunia Advisory 19 of 22 in 2007. 6,339 views.
Release Date:
2007-03-07
Secunia Advisory ID:
SA24405
Solution Status:
Partial Fix
Criticality:
Impact:
Manipulation of data
Privilege escalation
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS and IR, which can be exploited by malicious, local users to perform certain actions with escalated privileges. [Read More]


Avaya CMS xfs / X Render and DBE Extensions Vulnerabilities
Unpatched. Secunia Advisory 20 of 22 in 2007. 6,489 views.
Release Date:
2007-02-22
Secunia Advisory ID:
SA24247
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
System access
Where:
From local network
Short Description:
Avaya has acknowledged some vulnerabilities in Avaya CMS (Call Management System), which can be exploited by malicious, local users to gain escalated privileges or by malicious users to compromise a vulnerable system. [Read More]


Avaya CMS / IR Sun Solaris rpcbind Denial of Service
Vendor Patch. Secunia Advisory 21 of 22 in 2007. 6,488 views.
Release Date:
2007-02-05
Secunia Advisory ID:
SA24056
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Avaya has acknowledged a vulnerability in Avaya CMS / IR, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Avaya CMS / IR ld.so Directory Traversal and Buffer Overflow
Partial Fix. Secunia Advisory 22 of 22 in 2007. 5,938 views.
Release Date:
2007-01-30
Secunia Advisory ID:
SA23991
Solution Status:
Partial Fix
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Avaya has acknowledged a vulnerability and a security issue in Avaya CMS / IR, which can be exploited by malicious, local users to disclose sensitive information or potentially gain escalated privileges. [Read More]