CVE-2011-0960: SQL Injection
Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0960?
CVE-2011-0960 has a severity rating that suggests it can allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2011-0960?
To mitigate CVE-2011-0960, update Cisco Unified Operations Manager to version 8.6 or later.
Which versions of Cisco Unified Operations Manager are affected by CVE-2011-0960?
CVE-2011-0960 affects versions of Cisco Unified Operations Manager prior to 8.6.
What types of attacks can CVE-2011-0960 facilitate?
CVE-2011-0960 allows attackers to perform SQL injection attacks, enabling them to execute arbitrary SQL commands.
Is CVE-2011-0960 present in all versions of Cisco Unified Operations Manager?
No, CVE-2011-0960 is only present in versions of Cisco Unified Operations Manager before 8.6.