Known Vulnerabilities for products from Unify

Listed below are 11 of the newest known vulnerabilities associated with the vendor "Unify".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-64099 json Not Provided 2026-07-19 2026-07-20
CVE-2026-53015 json Not Provided 2026-06-24 2026-06-24
CVE-2024-42096 json Not Provided 2024-07-29 2026-05-12
CVE-2023-36619 json Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthentic... 9.8 - CRITICAL 2023-10-04 2023-10-06
CVE-2023-36618 json Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privi... 8.8 - HIGH 2023-10-04 2023-10-06
CVE-2015-8251 json OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, Ope... 5.9 - MEDIUM 2017-09-25 2017-10-11
CVE-2014-9563 json CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScap... 4.9 - MEDIUM 2018-04-12 2021-09-09
CVE-2014-8422 json The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices befor... 8.1 - HIGH 2018-04-12 2021-09-09
CVE-2014-8421 json Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain sup... 7.5 - HIGH 2018-04-12 2021-09-09
CVE-2014-2652 json SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers t... 9.8 - CRITICAL 2018-03-19 2018-04-20
CVE-2000-1114 json Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with chara... Not Provided 2001-01-09 2025-04-03
CVE-2000-1025 json eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service vi... Not Provided 2000-12-11 2025-04-03
CVE-2000-1024 json eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attack... Not Provided 2000-12-11 2025-04-03
CVE-2000-0498 json Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the ... Not Provided 2000-06-08 2025-04-03

Known software with vulnerabilities from Unify

Type Vendor Product Version
ApplicationUnifySqlbase Clients7.6.0
ApplicationUnifySqlbase Sqlconsole7.6.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report