QID 316971
Date Published: 2021-05-10
QID 316971: Cisco Unified Communications Manager IM and Presence Service SQL Injection Vulnerabilities(cisco-sa-imp-inj-ereCOKjR)
Multiple vulnerabilities in the web-based management interface of
Cisco Unified Communications Manager IM and Presence Service could allow an
authenticated, remote attacker to conduct SQL injection attacks on an affected system.
Affected Products
Following releases of Cisco Unified CM and Unified CM SME:
Prior to 11.5(1)SU9
From 12.0 Prior to 12.5(1)SU4
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.
A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database.
Solution
Customers are advised to refer to cisco-sa-imp-inj-ereCOKjR for more information.
Vendor References
- cisco-sa-imp-inj-ereCOKjR -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imp-inj-ereCOKjR
CVEs related to QID 316971
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-imp-inj-ereCOKjR |
|