QID 317166

Date Published: 2022-04-28

QID 317166: Cisco Unified Communications Manager IM and Presence Service SQL Injection Vulnerabilities (cisco-sa-imp-sqlinj-GrpUuQEJ)

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

Affected Products:
Cisco Unified Communications Manager releases: Earlier than 11.5(1) Prior to 11.5(1)SU11 From 12.5(1) Prior to 12.5(1)SU6 From 14 Prior to 14SU1 Note: No support for Cisco Unified Communications Manager Session Management Edition (Unified CM SME)

QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.

A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-imp-sqlinj-GrpUuQEJ for more information.

    CVEs related to QID 317166

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-imp-sqlinj-GrpUuQEJ URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imp-sqlinj-GrpUuQEJ