A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ip_office | Avaya | 10.0 (including) | 10.1.0.7 (including) |
Ip_office | Avaya | 11.0 (including) | 11.0.4.2 (including) |
Ip_office | Avaya | 9.0 (including) | 9.0 (including) |
Ip_office | Avaya | 9.0-sp1 (including) | 9.0-sp1 (including) |
Ip_office | Avaya | 9.0-sp10 (including) | 9.0-sp10 (including) |
Ip_office | Avaya | 9.0-sp11 (including) | 9.0-sp11 (including) |
Ip_office | Avaya | 9.0-sp12 (including) | 9.0-sp12 (including) |
Ip_office | Avaya | 9.0-sp2 (including) | 9.0-sp2 (including) |
Ip_office | Avaya | 9.0-sp3 (including) | 9.0-sp3 (including) |
Ip_office | Avaya | 9.0-sp4 (including) | 9.0-sp4 (including) |
Ip_office | Avaya | 9.0-sp5 (including) | 9.0-sp5 (including) |
Ip_office | Avaya | 9.0-sp6 (including) | 9.0-sp6 (including) |
Ip_office | Avaya | 9.0-sp7 (including) | 9.0-sp7 (including) |
Ip_office | Avaya | 9.0-sp8 (including) | 9.0-sp8 (including) |
Ip_office | Avaya | 9.0-sp9 (including) | 9.0-sp9 (including) |
Ip_office | Avaya | 9.1 (including) | 9.1 (including) |
Ip_office | Avaya | 9.1-sp1 (including) | 9.1-sp1 (including) |
Ip_office | Avaya | 9.1-sp10 (including) | 9.1-sp10 (including) |
Ip_office | Avaya | 9.1-sp11 (including) | 9.1-sp11 (including) |
Ip_office | Avaya | 9.1-sp12 (including) | 9.1-sp12 (including) |
Ip_office | Avaya | 9.1-sp3 (including) | 9.1-sp3 (including) |
Ip_office | Avaya | 9.1-sp4 (including) | 9.1-sp4 (including) |
Ip_office | Avaya | 9.1-sp5 (including) | 9.1-sp5 (including) |
Ip_office | Avaya | 9.1-sp6 (including) | 9.1-sp6 (including) |
Ip_office | Avaya | 9.1-sp7 (including) | 9.1-sp7 (including) |
Ip_office | Avaya | 9.1-sp8 (including) | 9.1-sp8 (including) |
Ip_office | Avaya | 9.1-sp9 (including) | 9.1-sp9 (including) |