CVE-2011-1609: SQL Injection
SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1609?
CVE-2011-1609 is classified as a high-severity SQL injection vulnerability allowing remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2011-1609?
To fix CVE-2011-1609, upgrade your Cisco Unified Communications Manager to a version that is patched, specifically 6.1(5)su2, 7.1(5)su1, 8.0(3), or 8.5(1) or later.
Who is affected by CVE-2011-1609?
CVE-2011-1609 affects installations of Cisco Unified Communications Manager versions prior to 6.1(5)su2, 7.1(5)su1, 8.0(3), and 8.5(1).
What can be exploited in CVE-2011-1609?
CVE-2011-1609 can be exploited to execute arbitrary SQL commands, potentially leading to unauthorized database access or manipulation.
Is there a workaround for CVE-2011-1609?
Currently, the only effective mitigation for CVE-2011-1609 is to upgrade to the patched versions of Cisco Unified Communications Manager.