Vulnerability Name: | CVE-2015-0699 (CCN-102287) | ||||||||
Assigned: | 2015-04-14 | ||||||||
Published: | 2015-04-14 | ||||||||
Updated: | 2017-01-06 | ||||||||
Summary: | SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut21563. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-0699 Source: CCN Type: Cisco Vulnerability Alert 38366 Cisco Unified Communications Manager Interactive Voice Response Interface SQL Injection Vulnerability Source: CISCO Type: Vendor Advisory 20150414 Cisco Unified Communications Manager Interactive Voice Response Interface SQL Injection Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1032134 Source: XF Type: UNKNOWN cisco-ucm-cve20150699-sql-injection(102287) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |