CVE-2014-3336

Cisco Unity Connection 9.1(2) and earlier - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95187
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69163
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59498
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030704

Scores

EPSS 0.0171
EPSS Percentile 75.0%

Details

CWE
CWE-89
Status published
Products (2)
cisco/unity_connection 9.1\(1\)
cisco/unity_connection 9.1\(2\)
Published Aug 11, 2014
Tracked Since Feb 18, 2026