Cisco Unified Communications Manager における SQL インジェクションの脆弱性
| Title |
Cisco Unified Communications Manager における SQL インジェクションの脆弱性
|
| Summary |
Cisco Unified Communications Manager には、SQL インジェクションの脆弱性が存在します。 ベンダは、本脆弱性を Bug ID CSCvg74810 として公開しています。
|
| Possible impacts |
情報を取得される可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
Feb. 7, 2018, midnight |
| Registration Date |
March 16, 2018, 3:34 p.m. |
| Last Update |
March 16, 2018, 3:34 p.m. |
|
CVSS3.0 : 警告
|
| Score |
4.3
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
|
CVSS2.0 : 警告
|
| Score |
4
|
| Vector |
AV:N/AC:L/Au:S/C:P/I:N/A:N |
Affected System
| シスコシステムズ |
|
Cisco Unified Communications Manager
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2018年03月16日] 掲載 |
March 16, 2018, 3:34 p.m. |
NVD Vulnerability Information
CVE-2018-0120
| Summary |
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct an SQL injection attack against an affected system. The vulnerability exists because the affected software fails to validate user-supplied input in certain SQL queries that bypass protection filters. An attacker could exploit this vulnerability by submitting crafted HTTP requests that contain malicious SQL statements to an affected system. A successful exploit could allow the attacker to determine the presence of certain values in the database of the affected system. Cisco Bug IDs: CSCvg74810.
|
| Publication Date |
Feb. 8, 2018, 4:29 p.m. |
| Registration Date |
March 1, 2021, 6:35 p.m. |
| Last Update |
Nov. 21, 2024, 12:37 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.13900.52\):*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List