ID

VAR-201408-0162


CVE

CVE-2014-3339


TITLE

Cisco Unified Communications Manager and Cisco Unified Presence Server Management Web In the interface SQL Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-003798

DESCRIPTION

Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL commands via crafted input to unspecified pages, aka Bug ID CSCup74290. An authenticated attacker can leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. This issue is tracked by Cisco Bug ID CSCup74290. CUCM is a call processing component in a unified communication system, which provides a scalable, distributed and highly available enterprise IP phone call processing solution

Trust: 1.98

sources: NVD: CVE-2014-3339 // JVNDB: JVNDB-2014-003798 // BID: 69200 // VULHUB: VHN-71279

AFFECTED PRODUCTS

vendor:ciscomodel:unified communications domain managerscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:unified presence serverscope: - version: -

Trust: 1.4

vendor:ciscomodel:unified presence serverscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:unified communications managerscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2014-003798 // CNNVD: CNNVD-201408-224 // NVD: CVE-2014-3339

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3339
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3339
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201408-224
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71279
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3339
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-71279
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-71279 // JVNDB: JVNDB-2014-003798 // CNNVD: CNNVD-201408-224 // NVD: CVE-2014-3339

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.9

sources: VULHUB: VHN-71279 // JVNDB: JVNDB-2014-003798 // NVD: CVE-2014-3339

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201408-224

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-201408-224

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003798

PATCH

title:Cisco Unified Communications Manager and Cisco Unified Presence Server SQL Injection Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3339

Trust: 0.8

title:35275url:http://tools.cisco.com/security/center/viewAlert.x?alertId=35275

Trust: 0.8

sources: JVNDB: JVNDB-2014-003798

EXTERNAL IDS

db:NVDid:CVE-2014-3339

Trust: 2.8

db:BIDid:69200

Trust: 1.4

db:JVNDBid:JVNDB-2014-003798

Trust: 0.8

db:CNNVDid:CNNVD-201408-224

Trust: 0.7

db:VULHUBid:VHN-71279

Trust: 0.1

sources: VULHUB: VHN-71279 // BID: 69200 // JVNDB: JVNDB-2014-003798 // CNNVD: CNNVD-201408-224 // NVD: CVE-2014-3339

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3339

Trust: 1.7

url:http://www.securityfocus.com/bid/69200

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/95250

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3339

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3339

Trust: 0.8

url:http://www.cisco.com

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps7060/index.html

Trust: 0.3

sources: VULHUB: VHN-71279 // BID: 69200 // JVNDB: JVNDB-2014-003798 // CNNVD: CNNVD-201408-224 // NVD: CVE-2014-3339

CREDITS

Cisco

Trust: 0.3

sources: BID: 69200

SOURCES

db:VULHUBid:VHN-71279
db:BIDid:69200
db:JVNDBid:JVNDB-2014-003798
db:CNNVDid:CNNVD-201408-224
db:NVDid:CVE-2014-3339

LAST UPDATE DATE

2024-11-23T23:09:22.372000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-71279date:2017-08-29T00:00:00
db:BIDid:69200date:2014-08-14T00:02:00
db:JVNDBid:JVNDB-2014-003798date:2014-08-15T00:00:00
db:CNNVDid:CNNVD-201408-224date:2014-08-14T00:00:00
db:NVDid:CVE-2014-3339date:2024-11-21T02:07:53.813

SOURCES RELEASE DATE

db:VULHUBid:VHN-71279date:2014-08-12T00:00:00
db:BIDid:69200date:2014-08-12T00:00:00
db:JVNDBid:JVNDB-2014-003798date:2014-08-15T00:00:00
db:CNNVDid:CNNVD-201408-224date:2014-08-14T00:00:00
db:NVDid:CVE-2014-3339date:2014-08-12T23:55:03.957