Multiple vulnerabilities have been identified in Avaya SIP Enablement Services (SES), which could be exploited by attackers or malicious users to gain knowledge of sensitive information or compromise a vulnerable system. These issues are caused by input validation errors in the Web management interface when processing user-supplied data, which could allow remote attackers to gain unauthorized access to several files without authentication, or execute arbitrary code.