CVE-2017-6668

CWE-89SQL Injection4 documents4 sources
Severity
4.9MEDIUM
EPSS
0.2%
top 57.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 17

Description

Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5cisco_unified_communications_domain_managerCisco Unified Communications Domain Manager

🔴Vulnerability Details

2
GHSA
GHSA-xr99-57mh-xrxf: Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact th2022-05-17
CVEList
CVE-2017-6668: Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact th2017-06-13

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities2017-06-07
CVE-2017-6668 (MEDIUM CVSS 4.9) | Vulnerabilities in the web-based GU | cvebase.io