ID

VAR-201509-0019


CVE

CVE-2015-6299


TITLE

Cisco Unity Connection of Web In the interface SQL Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-004945

DESCRIPTION

SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824. Cisco Unity Connection is a feature-rich voice messaging platform that uses the Linux Unified Communications operating system. A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. This issue is being tracked by Cisco Bug ID CSCuv63824. The platform can use voice commands to make calls or listen to messages "hands-free"

Trust: 2.52

sources: NVD: CVE-2015-6299 // JVNDB: JVNDB-2015-004945 // CNVD: CNVD-2015-06208 // BID: 76790 // VULHUB: VHN-84260

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-06208

AFFECTED PRODUCTS

vendor:ciscomodel:unity connectionscope:eqversion:9.1\(2\)

Trust: 1.6

vendor:ciscomodel:unity connectionscope:eqversion:9.1\(1\)

Trust: 1.6

vendor:ciscomodel:unity connectionscope:eqversion:9.1 (1)

Trust: 0.8

vendor:ciscomodel:unity connectionscope:eqversion:9.1 (2)

Trust: 0.8

vendor:ciscomodel:unity connectionscope:lteversion:<=9.1(1.2)

Trust: 0.6

vendor:ciscomodel:unity connectionscope:eqversion:9.1(2)

Trust: 0.3

vendor:ciscomodel:unity connectionscope:eqversion:9.1(1)

Trust: 0.3

sources: CNVD: CNVD-2015-06208 // BID: 76790 // JVNDB: JVNDB-2015-004945 // CNNVD: CNNVD-201509-382 // NVD: CVE-2015-6299

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6299
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6299
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-06208
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201509-382
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84260
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6299
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-06208
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-84260
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-06208 // VULHUB: VHN-84260 // JVNDB: JVNDB-2015-004945 // CNNVD: CNNVD-201509-382 // NVD: CVE-2015-6299

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.9

sources: VULHUB: VHN-84260 // JVNDB: JVNDB-2015-004945 // NVD: CVE-2015-6299

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201509-382

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-201509-382

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004945

PATCH

title:41074url:http://tools.cisco.com/security/center/viewAlert.x?alertId=41074

Trust: 0.8

sources: JVNDB: JVNDB-2015-004945

EXTERNAL IDS

db:NVDid:CVE-2015-6299

Trust: 3.4

db:SECTRACKid:1033622

Trust: 1.1

db:JVNDBid:JVNDB-2015-004945

Trust: 0.8

db:CNNVDid:CNNVD-201509-382

Trust: 0.7

db:CNVDid:CNVD-2015-06208

Trust: 0.6

db:BIDid:76790

Trust: 0.4

db:VULHUBid:VHN-84260

Trust: 0.1

sources: CNVD: CNVD-2015-06208 // VULHUB: VHN-84260 // BID: 76790 // JVNDB: JVNDB-2015-004945 // CNNVD: CNNVD-201509-382 // NVD: CVE-2015-6299

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=41074

Trust: 2.6

url:http://www.securitytracker.com/id/1033622

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6299

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6299

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2015-06208 // VULHUB: VHN-84260 // BID: 76790 // JVNDB: JVNDB-2015-004945 // CNNVD: CNNVD-201509-382 // NVD: CVE-2015-6299

CREDITS

Cisco

Trust: 0.3

sources: BID: 76790

SOURCES

db:CNVDid:CNVD-2015-06208
db:VULHUBid:VHN-84260
db:BIDid:76790
db:JVNDBid:JVNDB-2015-004945
db:CNNVDid:CNNVD-201509-382
db:NVDid:CVE-2015-6299

LAST UPDATE DATE

2024-11-23T23:02:39.948000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-06208date:2015-09-24T00:00:00
db:VULHUBid:VHN-84260date:2016-12-29T00:00:00
db:BIDid:76790date:2015-09-18T00:00:00
db:JVNDBid:JVNDB-2015-004945date:2015-09-30T00:00:00
db:CNNVDid:CNNVD-201509-382date:2015-09-21T00:00:00
db:NVDid:CVE-2015-6299date:2024-11-21T02:34:43.810

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-06208date:2015-09-24T00:00:00
db:VULHUBid:VHN-84260date:2015-09-20T00:00:00
db:BIDid:76790date:2015-09-18T00:00:00
db:JVNDBid:JVNDB-2015-004945date:2015-09-30T00:00:00
db:CNNVDid:CNNVD-201509-382date:2015-09-21T00:00:00
db:NVDid:CVE-2015-6299date:2015-09-20T14:59:04.943