CVE-2017-6668
published 2017-06-13CVE-2017-6668: Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the…
PriorityP432medium4.9CVSS 3.0
AVNACLPRHUINSUCHINAN
EPSS
1.31%
67.4th percentile
Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities
vendor_cisco·2017-06-07·CVSS 4.1
CVE-2017-6668 [MEDIUM] CWE-89 Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities
Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities
Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries.
The vulnerabilities are due to insufficient validation of user-supplied input in HTTP request parameters. An attacker could exploit these vulnerabilities by submitting a crafted HTTP request that contains a malicious SQL statement to the web interface of the affected software. An exploit could allow the attacker to retrieve certain data from the SQL database used by CUCDM. Modifying data in the SQL database is not possible.
There are no workarounds that address this vulnerability.
This advisory is a
Cisco
Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2017-6668 Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities
CVE-2017-6668: Cisco Unified Communications Domain Manager SQL Injection Vulnerabilities
Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries. The vulnerabilities are due to insufficient validation of user-supplied input in HTTP request parameters. An attacker could exploit these vulnerabilities by submitting a crafted HTTP request that contains a malicious SQL statement to the web interface of the affected software. An exploit could allow the attacker to retrieve certain data from the SQL database used by CUCDM. Modifying data in the SQL database is not possible. There are no
CVSS: 3.0
CWE: CWE-89, CWE-89
Bug IDs: CSCvc52784, C
GHSA
GHSA-xr99-57mh-xrxf: Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact th
ghsa_unreviewed·2022-05-17
CVE-2017-6668 [MEDIUM] CWE-89 GHSA-xr99-57mh-xrxf: Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact th
Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98947http://www.securitytracker.com/id/1038632https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-cucm2http://www.securityfocus.com/bid/98947http://www.securitytracker.com/id/1038632https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-cucm2
2017-06-13
Published