Skip to main content

Vendor/product archive

cisco / unified_communications_manager CVEs

Beta · best-effort

238 CVEs tagged to cisco / unified_communications_manager11 Critical, 76 High, 149 Medium, 1 Low, 1 Unrated.

CVE-2014-3287

Published Jun 10, 2014

SQL injection vulnerability in BulkViewFileContentsAction.java in the Java interface in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to exec…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2185

Published Apr 29, 2014

The Call Detail Records (CDR) Management component in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive information by readin…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2184

Published Apr 29, 2014

The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers to obtain sensitive information via a crafted URL, aka Bug I…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0747

Published Feb 27, 2014

The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to inject commands v…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0743

Published Feb 27, 2014

The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0742

Published Feb 27, 2014

The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows lo…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0741

Published Feb 27, 2014

The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allow…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0740

Published Feb 27, 2014

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communication…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0731

Published Feb 22, 2014

The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0733

Published Feb 20, 2014

The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0736

Published Feb 20, 2014

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earli…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0735

Published Feb 20, 2014

Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0734

Published Feb 20, 2014

SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0732

Published Feb 20, 2014

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0729

Published Feb 13, 2014

SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitrary SQL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0728

Published Feb 13, 2014

SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL comma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0727

Published Feb 13, 2014

SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0726

Published Feb 13, 2014

SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0725

Published Feb 13, 2014

Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified acc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0724

Published Feb 13, 2014

The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by us…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0723

Published Feb 13, 2014

Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0722

Published Feb 13, 2014

The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0686

Published Feb 4, 2014

Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCu…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0657

Published Jan 8, 2014

The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated use…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6978

Published Dec 21, 2013

The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device informat…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 238 CVEsPage 6 of 10