CVE-2011-1609
Summary
| CVE | CVE-2011-1609 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-05-03 22:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Unified Communications Manager | 6.0 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(1a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(1b\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(1\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(2\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(2\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(2\)su1a | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(3a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(3b\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(3b\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(3\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(4a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(4a\)su2 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(4\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(4\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(5\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 6.1\(5\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0\(1\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0\(1\)su1a | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0\(2a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0\(2a\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0\(2a\)su2 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.0\(2\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(2a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(2a\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(2b\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(3a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(3a\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(3a\)su1a | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(3b\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(3b\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(3b\)su2 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(3\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(5a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(5b\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(5\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(5\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 7.1\(5\)su1a | All | All | All |
| Application | Cisco | Unified Communications Manager | 8.0\(2c\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 8.0\(2c\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 8.0\(3a\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 8.0\(3a\)su1 | All | All | All |
| Application | Cisco | Unified Communications Manager | 8.0\(3a\)su2 | All | All | All |
| Application | Cisco | Unified Communications Manager | 8.0\(3\) | All | All | All |
| Application | Cisco | Unified Communications Manager | 8.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Unified Communications Manager (CVE-2011-1609) SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Unified Communications Manager Multiple Bugs Let Remote Users Deny Service, Inject SQL Commands, and Upload Arbitrary Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Cisco Systems - Redirect to | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.