SQL Injection Vulnerabilities in Cisco Unified Communications Manager and Presence Server
CVE-2014-3339

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
12 August 2014

Summary

Multiple SQL injection vulnerabilities exist within the administrative web interface of Cisco Unified Communications Manager and Cisco Unified Presence Server. These vulnerabilities allow remote authenticated users to execute arbitrary SQL commands through carefully crafted inputs sent to specific pages of the affected applications. This unauthorized access can compromise the integrity of the database and expose sensitive data, posing significant risks to organizations relying on these communication solutions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.