ID

VAR-201402-0204


CVE

CVE-2014-0726


TITLE

Cisco Unified Communications Manager of IP Manager Assistant In the interface SQL Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-001400

DESCRIPTION

SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05326. A successful exploit may allow an authenticated attacker to compromise the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database. This issue is tracked by Cisco Bug ID CSCum05326. Cisco Unified Communications Manager (CUCM, Unified CM, CallManager) is a call processing component in a unified communication system of Cisco (Cisco). This component provides a scalable, distributed and highly available enterprise IP telephony call processing solution

Trust: 1.98

sources: NVD: CVE-2014-0726 // JVNDB: JVNDB-2014-001400 // BID: 65514 // VULHUB: VHN-68219

AFFECTED PRODUCTS

vendor:ciscomodel:unified communications managerscope:eqversion:10.0

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:lteversion:10.0\(1\)

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:lteversion:10.0(1)

Trust: 0.8

vendor:ciscomodel:unified communications managerscope:eqversion:10.0\(1\)

Trust: 0.6

sources: JVNDB: JVNDB-2014-001400 // CNNVD: CNNVD-201402-153 // NVD: CVE-2014-0726

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0726
value: HIGH

Trust: 1.0

NVD: CVE-2014-0726
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201402-153
value: HIGH

Trust: 0.6

VULHUB: VHN-68219
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-0726
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-68219
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-68219 // JVNDB: JVNDB-2014-001400 // CNNVD: CNNVD-201402-153 // NVD: CVE-2014-0726

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.9

sources: VULHUB: VHN-68219 // JVNDB: JVNDB-2014-001400 // NVD: CVE-2014-0726

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201402-153

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-201402-153

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001400

PATCH

title:Cisco Unified Communications Manager IPMA Blind SQL Injection Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0726

Trust: 0.8

title:32843url:http://tools.cisco.com/security/center/viewAlert.x?alertId=32843

Trust: 0.8

sources: JVNDB: JVNDB-2014-001400

EXTERNAL IDS

db:NVDid:CVE-2014-0726

Trust: 2.8

db:BIDid:65514

Trust: 1.4

db:OSVDBid:103218

Trust: 1.1

db:JVNDBid:JVNDB-2014-001400

Trust: 0.8

db:CNNVDid:CNNVD-201402-153

Trust: 0.7

db:CISCOid:20140212 CISCO UNIFIED COMMUNICATIONS MANAGER IPMA BLIND SQL INJECTION VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-68219

Trust: 0.1

sources: VULHUB: VHN-68219 // BID: 65514 // JVNDB: JVNDB-2014-001400 // CNNVD: CNNVD-201402-153 // NVD: CVE-2014-0726

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-0726

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=32843

Trust: 1.7

url:http://www.securityfocus.com/bid/65514

Trust: 1.1

url:http://osvdb.org/103218

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0726

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0726

Trust: 0.8

url:http://www.cisco.com

Trust: 0.3

sources: VULHUB: VHN-68219 // BID: 65514 // JVNDB: JVNDB-2014-001400 // CNNVD: CNNVD-201402-153 // NVD: CVE-2014-0726

CREDITS

Cisco

Trust: 0.3

sources: BID: 65514

SOURCES

db:VULHUBid:VHN-68219
db:BIDid:65514
db:JVNDBid:JVNDB-2014-001400
db:CNNVDid:CNNVD-201402-153
db:NVDid:CVE-2014-0726

LAST UPDATE DATE

2024-11-23T22:13:49.886000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-68219date:2015-09-16T00:00:00
db:BIDid:65514date:2014-02-12T00:00:00
db:JVNDBid:JVNDB-2014-001400date:2014-02-14T00:00:00
db:CNNVDid:CNNVD-201402-153date:2014-03-10T00:00:00
db:NVDid:CVE-2014-0726date:2024-11-21T02:02:41.810

SOURCES RELEASE DATE

db:VULHUBid:VHN-68219date:2014-02-13T00:00:00
db:BIDid:65514date:2014-02-12T00:00:00
db:JVNDBid:JVNDB-2014-001400date:2014-02-14T00:00:00
db:CNNVDid:CNNVD-201402-153date:2014-02-17T00:00:00
db:NVDid:CVE-2014-0726date:2014-02-13T05:24:51.573