CVE-2017-3886
MEDIUMCisco Unified Communications Manager - SQL Injection
Title source: llmDescription
A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The attacker must be authenticated as an administrative user to execute SQL database queries. More Information: CSCvc74291. Known Affected Releases: 1.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 12.0(0.98000.619) 12.0(0.98000.485) 12.0(0.98000.212) 11.5(1.13035.1) 11.0(1.23900.5) 11.0(1.23900.2) 11.0(1.23067.1) 10.5(2.15900.2).
Scores
CVSS v3
4.9
EPSS
0.0020
EPSS Percentile
42.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-89
Status
published
Affected Products (3)
cisco/unified_communications_manager
cisco/unified_communications_manager
n/a/Cisco Unified Communications Manager
< Cisco Unified Communications Manager
Timeline
Published
Apr 07, 2017
Tracked Since
Feb 18, 2026