CVE-2014-0728: SQL Injection
Published Feb 13, 2014
·Updated
SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05313.
Affected Software
2 affected components
Cisco Unified Communications Manager<=10.0\(1\)
Cisco Unified Communications Manager=10.0
Event History
Feb 13, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·05:24 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0728?
CVE-2014-0728 has been assigned a high severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2014-0728?
To fix CVE-2014-0728, upgrade your Cisco Unified Communications Manager to a version later than 10.0(1) that addresses this vulnerability.
3
Which versions of Cisco Unified Communications Manager are affected by CVE-2014-0728?
CVE-2014-0728 affects Cisco Unified Communications Manager versions 10.0(1) and earlier.
4
What type of vulnerability is CVE-2014-0728?
CVE-2014-0728 is classified as an SQL injection vulnerability allowing for remote exploitation.
5
Can CVE-2014-0728 be exploited remotely?
Yes, CVE-2014-0728 can be exploited remotely via a crafted URL.