SQL Injection Vulnerability in Cisco Unified Communications Manager (UCM) IP Manager Assistant (IPMA) Interface

SQL Injection Vulnerability in Cisco Unified Communications Manager (UCM) IP Manager Assistant (IPMA) Interface

CVE-2014-0726 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05326.

Learn more about our Cis Benchmark Audit For Cisco.