CVE-2015-0699
published 2015-04-15CVE-2015-0699: SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote…
PriorityP336medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.89%
77.2th percentile
SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut21563.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6m8-h84x-xg8h: SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10
ghsa_unreviewed·2022-05-17
CVE-2015-0699 [MEDIUM] CWE-89 GHSA-f6m8-h84x-xg8h: SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10
SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut21563.
Cisco
Cisco Unified Communications Manager Interactive Voice Response Interface SQL Injection Vulnerability
vendor_cisco·2015-04-14·CVSS 5.0
CVE-2015-0699 [MEDIUM] CWE-89 Cisco Unified Communications Manager Interactive Voice Response Interface SQL Injection Vulnerability
Cisco Unified Communications Manager Interactive Voice Response Interface SQL Injection Vulnerability
A vulnerability in the Interactive Voice Response (IVR) interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct SQL injection attacks.
The vulnerability is due to a lack of input validation on user-supplied input within SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected system. A successful exploit could allow the attacker to determine the presence of certain values in the database, which could be leveraged to conduct further attacks.
Cisco has confirmed the vulnerability; however, software updates are not available.
Cisco indicates through th
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-15
Published