This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:SQL:INJ:CISCO-UCM
|
Severity |
Minor
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Cisco Unified Communications Manager SQL Injection
|
Release Date |
2011/05/12
|
Update Number |
1919
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Cisco Unified Communications Manager SQL Injection
This signature detects attempts to exploit a known vulnerability in Cisco Unified Communications Manager. It is due to insufficient validation of user-supplied input. An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
Extended Description
Cisco Unified Communications Manager is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an authenticated attacker to compromise the affected device, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is tracked by Cisco Bug ID CSCtj42064.
Affected Products
- Cisco unified_communications_manager 6.0(1)
- Cisco unified_communications_manager 6.0 (1A)
- Cisco unified_communications_manager 6.1
- Cisco unified_communications_manager 6.1(1)
- Cisco unified_communications_manager 6.1(1A)
- Cisco unified_communications_manager 6.1(1B)
- Cisco unified_communications_manager 6.1(2)
- Cisco unified_communications_manager 6.1 (2)Su1
- Cisco unified_communications_manager 6.1(2)Su1a
- Cisco unified_communications_manager 6.1(3)
- Cisco unified_communications_manager 6.1(3A)
- Cisco unified_communications_manager 6.1(3B)
- Cisco unified_communications_manager 6.1 (3B)Su1
- Cisco unified_communications_manager 6.1(4)
- Cisco unified_communications_manager 6.1(4A)
- Cisco unified_communications_manager 6.1(4A)Su2
- Cisco unified_communications_manager 6.1(4)Su1
- Cisco unified_communications_manager 6.1(5)
- Cisco unified_communications_manager 6.1(5)SU1
- Cisco unified_communications_manager 6.1(5)SU2
- Cisco unified_communications_manager 7.0
- Cisco unified_communications_manager 7.0(1)Su1
- Cisco unified_communications_manager 7.0(1)Su1a
- Cisco unified_communications_manager 7.0(2)
- Cisco unified_communications_manager 7.0(2A)
- Cisco unified_communications_manager 7.0(2A)Su1
- Cisco unified_communications_manager 7.0(2A)Su2
- Cisco unified_communications_manager 7.0(2a)SU3
- Cisco unified_communications_manager 7.0(2a)SU3
- Cisco unified_communications_manager 7.0(3G)
- Cisco unified_communications_manager 7.1
- Cisco unified_communications_manager 7.1(2)
- Cisco unified_communications_manager 7.1(2A)
- Cisco unified_communications_manager 7.1(2A)Su1
- Cisco unified_communications_manager 7.1(2B)
- Cisco unified_communications_manager 7.1(2B)Su1
- Cisco unified_communications_manager 7.1(3)
- Cisco unified_communications_manager 7.1(3A)
- Cisco unified_communications_manager 7.1(3A)Su1
- Cisco unified_communications_manager 7.1(3A)Su1a
- Cisco unified_communications_manager 7.1(3B)
- Cisco unified_communications_manager 7.1(3B)Su1
- Cisco unified_communications_manager 7.1(3B)Su2
- Cisco unified_communications_manager 7.1(5)
- Cisco unified_communications_manager 7.1(5A)
- Cisco unified_communications_manager 7.1(5B)
- Cisco unified_communications_manager 7.1(5b)SU2
- Cisco unified_communications_manager 7.1(5)Su1
- Cisco unified_communications_manager 7.1(5)Su1a
- Cisco unified_communications_manager 8.0(0.98000.106)
- Cisco unified_communications_manager 8.0(1)
- Cisco unified_communications_manager 8.0(2C)
- Cisco unified_communications_manager 8.0(2C)Su1
- Cisco unified_communications_manager 8.0(3)
- Cisco unified_communications_manager 8.0(3a)
- Cisco unified_communications_manager 8.5
References