First published: Thu Feb 13 2014(Updated: )
SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05302.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager Session Management Edition |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0729 has been assigned a high severity rating due to its potential for remote SQL injection attacks.
To fix CVE-2014-0729, ensure you update to the latest version of Cisco Unified Communications Manager that addresses this vulnerability.
CVE-2014-0729 affects users of Cisco Unified Communications Manager, particularly those using vulnerable versions of the Enterprise Mobility Application.
Exploiting CVE-2014-0729 allows remote attackers to execute arbitrary SQL commands, potentially leading to data leakage and unauthorized access.
While the best approach is to apply the security update, temporarily restricting access to the affected services can mitigate the risk of exploitation for CVE-2014-0729.