Vulnerabilities > Cisco > Unified Communications Manager > 8.5.1.su4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-07-18 | CVE-2013-3404 | SQL Injection vulnerability in Cisco Unified Communications Manager SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug ID CSCuh01051. | 7.5 |
2013-07-18 | CVE-2013-3403 | Unspecified vulnerability in Cisco Unified Communications Manager Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCuh73454. | 6.8 |
2013-07-18 | CVE-2013-3402 | Code Injection vulnerability in Cisco Unified Communications Manager An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440. | 6.5 |