Known Vulnerabilities for Unified Meetingplace by Cisco

Listed below are 10 of the newest known vulnerabilities associated with "Unified Meetingplace" by "Cisco".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2015-4233 SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL... 6.5 - MEDIUM 2015-07-02 2016-12-28
CVE-2015-4214 Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading... 4 - MEDIUM 2015-06-24 2016-12-28
CVE-2015-0764 Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug I... 5 - MEDIUM 2015-06-04 2017-01-04
CVE-2015-0763 Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obt... 5 - MEDIUM 2015-06-04 2017-01-04
CVE-2015-0762 Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) for ... 4.3 - MEDIUM 2015-06-04 2017-01-04
CVE-2015-0758 The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via an XM... 4 - MEDIUM 2015-05-30 2017-01-04
CVE-2015-0705 Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified Meet... 6.8 - MEDIUM 2015-04-22 2017-01-06
CVE-2015-0704 Multiple cross-site request forgery (CSRF) vulnerabilities in API features in Cisco Unified MeetingPlace 8.6(1.9) allow remot... 6.8 - MEDIUM 2015-04-22 2017-01-06
CVE-2015-0703 Cross-site scripting (XSS) vulnerability in the administrative web interface in Cisco Unified MeetingPlace 8.6(1.9) allows re... 4.3 - MEDIUM 2015-04-21 2017-01-06
CVE-2015-0702 Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) all... 9 - HIGH 2015-04-21 2017-01-06

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCiscoUnified Meetingplace8.6\(1.9\)AllAllAll
ApplicationCiscoUnified Meetingplace8.6\(1.2\)AllAllAll
ApplicationCiscoUnified Meetingplace8.5.4AllAllAll
ApplicationCiscoUnified Meetingplace8.5.3AllAllAll
ApplicationCiscoUnified Meetingplace8.5.2AllAllAll
ApplicationCiscoUnified Meetingplace8.5.1AllAllAll
ApplicationCiscoUnified Meetingplace8.5AllAllAll
ApplicationCiscoUnified Meetingplace8.0mr1AllAll
ApplicationCiscoUnified Meetingplace8.0AllAllAll
ApplicationCiscoUnified Meetingplace7.1AllAllAll
ApplicationCiscoUnified Meetingplace7.1mr1AllAll
ApplicationCiscoUnified Meetingplace7.0.3mr2AllAll
ApplicationCiscoUnified Meetingplace7.0.3AllAllAll
ApplicationCiscoUnified Meetingplace7.0.2mr1AllAll
ApplicationCiscoUnified Meetingplace7.0.2AllAllAll
ApplicationCiscoUnified Meetingplace7.0.1AllAllAll
ApplicationCiscoUnified Meetingplace7.0AllAllAll
ApplicationCiscoUnified Meetingplace6.1AllAllAll
ApplicationCiscoUnified Meetingplace6.0AllAllAll
ApplicationCiscoUnified Meetingplace5.4AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report