CVE-2014-0734SQL Injection in Cisco Unified Communications Manager

CWE-89SQL Injection4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.2%
top 55.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 17

Description

SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum46483.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-4c72-3jr9-g459: SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 102022-05-17
CVEList
CVE-2014-0734: SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 102014-02-20

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager CAPF Unauthenticated Blind SQL Injection Vulnerability2014-02-19
CVE-2014-0734 — SQL Injection in Cisco | cvebase