Skip to main content

Vendor/product archive

cisco / unified_communications_domain_manager CVEs

Beta · best-effort

41 CVEs tagged to cisco / unified_communications_domain_manager3 Critical, 2 High, 36 Medium, 0 Low, 0 Unrated.

CVE-2018-0124

Published Feb 22, 2018

A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execut…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12302

Published Nov 16, 2017

A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by exe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6670

Published Jun 13, 2017

A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6668

Published Jun 13, 2017

Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the syst…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1354

Published Mar 3, 2016

Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4196

Published Jul 4, 2015

Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0699

Published Apr 15, 2015

SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote attackers to execute arb…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0684

Published Apr 3, 2015

SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL comm…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0591

Published Jan 15, 2015

Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood of malformed TCP packets, aka B…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0588

Published Jan 15, 2015

Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authentication of arbitrary users, a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8018

Published Dec 22, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 al…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8010

Published Dec 10, 2014

The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3337

Published Aug 12, 2014

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafte…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3320

Published Jul 18, 2014

Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Communications Domain Manager (CDM) 8.1(.4) and earlier allow remote attack…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2