Vulnerability Description
Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL commands via crafted input to unspecified pages, aka Bug ID CSCup74290.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Domain Manager | - |
| Cisco | Unified Presence Server | All versions |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3339Vendor Advisory
- http://www.securityfocus.com/bid/69200
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95250
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3339Vendor Advisory
- http://www.securityfocus.com/bid/69200
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95250
FAQ
What is CVE-2014-3339?
CVE-2014-3339 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to exe...
How severe is CVE-2014-3339?
CVE-2014-3339 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3339?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Communications Domain Manager, Cisco Unified Presence Server.