Lucene search

K
ciscoCiscoCISCO-SA-20120510-CVE-2012-0337
HistoryMay 10, 2012 - 9:06 p.m.

Cisco Unified MeetingPlace SQL Injection Vulnerability

2012-05-1021:06:01
tools.cisco.com
8

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.001

Percentile

41.7%

Cisco Unified MeetingPlace contains a vulnerability that could allow an authenticated, remote attacker to execute arbitrary SQL code on a targeted system.

The vulnerability is due to improper validation of user-supplied input to the web-based application interface. An authenticated, remote attacker could exploit this vulnerability by sending malicious requests to the system. If successful, the attacker could execute arbitrary SQL code against the database underlying the affected application.

Cisco has confirmed this vulnerability in a bug report and has released updated software.

To exploit this vulnerability, the attacker would need to authenticate to the targeted device. To achieve this objective, the attacker may need access to trusted, internal network resources. This access requirement reduces the exposure of this vulnerability.

Affected configurations

Vulners
Node
ciscounified_meetingplace_web_conferencingMatchany
OR
ciscounified_meetingplace_web_conferencingMatchany
VendorProductVersionCPE
ciscounified_meetingplace_web_conferencinganycpe:2.3:a:cisco:unified_meetingplace_web_conferencing:any:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.001

Percentile

41.7%

Related for CISCO-SA-20120510-CVE-2012-0337