CVE-2017-3886
published 2017-04-07CVE-2017-3886: A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the…
PriorityP335medium4.9CVSS 3.0
AVNACLPRHUINSUCHINAN
EPSS
1.88%
77.2th percentile
A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The attacker must be authenticated as an administrative user to execute SQL database queries. More Information: CSCvc74291. Known Affected Releases: 1.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 12.0(0.98000.619) 12.0(0.98000.485) 12.0(0.98000.212) 11.5(1.13035.1) 11.0(1.23900.5) 11.0(1.23900.2) 11.0(1.23067.1) 10.5(2.15900.2).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager SQL Injection Vulnerability
vendor_cisco·2017-04-05·CVSS 4.9
CVE-2017-3886 [MEDIUM] CWE-89 Cisco Unified Communications Manager SQL Injection Vulnerability
Cisco Unified Communications Manager SQL Injection Vulnerability
A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries. The attacker must be authenticated as an administrative user to execute SQL database queries.
The vulnerability is due to a lack of input validation on HTTP requests that contain user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP requests that contain malicious SQL statements to the affected system. An exploit could allow the attacker to determine the presence of certain values in the database.
Additional information is available at the following link:
https://www.owasp.org/index.php/SQL_
Cisco
Cisco Unified Communications Manager SQL Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3886 Cisco Unified Communications Manager SQL Injection Vulnerability
CVE-2017-3886: Cisco Unified Communications Manager SQL Injection Vulnerability
A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries. The attacker must be authenticated as an administrative user to execute SQL database queries. The vulnerability is due to a lack of input validation on HTTP requests that contain user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP requests that contain malicious SQL statements to the affected system. An exploit could allow the attacker to determine the presence of certain values in the database. Additional information is available at the following link: https://www.owasp.org/in
GHSA
GHSA-gfv7-h45g-g54g: A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality
ghsa_unreviewed·2022-05-17
CVE-2017-3886 [MEDIUM] CWE-89 GHSA-gfv7-h45g-g54g: A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality
A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The attacker must be authenticated as an administrative user to execute SQL database queries. More Information: CSCvc74291. Known Affected Releases: 1.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 12.0(0.98000.619) 12.0(0.98000.485) 12.0(0.98000.212) 11.5(1.13035.1) 11.0(1.23900.5) 11.0(1.23900.2) 11.0(1.23067.1) 10.5(2.15900.2).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/97432http://www.securitytracker.com/id/1038192https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ucmhttp://www.securityfocus.com/bid/97432http://www.securitytracker.com/id/1038192https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ucm
2017-04-07
Published