Lucene search

K
ciscoCiscoCISCO-SA-20170607-CUCM2
HistoryJun 07, 2017 - 4:00 p.m.

Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities

2017-06-0716:00:00
tools.cisco.com
17

EPSS

0.001

Percentile

40.0%

Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries.

The vulnerabilities are due to insufficient validation of user-supplied input in HTTP request parameters. An attacker could exploit these vulnerabilities by submitting a crafted HTTP request that contains a malicious SQL statement to the web interface of the affected software. An exploit could allow the attacker to retrieve certain data from the SQL database used by CUCDM. Modifying data in the SQL database is not possible.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-cucm2 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-cucm2”]

Affected configurations

Vulners
Node
ciscounified_communications_domain_managerMatchany
OR
ciscounified_communications_domain_managerMatchany
VendorProductVersionCPE
ciscounified_communications_domain_manageranycpe:2.3:a:cisco:unified_communications_domain_manager:any:*:*:*:*:*:*:*

EPSS

0.001

Percentile

40.0%

Related for CISCO-SA-20170607-CUCM2