CVE-2014-0734: SQL Injection
SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum46483.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0734?
The severity of CVE-2014-0734 is classified as high due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2014-0734?
To fix CVE-2014-0734, upgrade to the latest version of Cisco Unified Communications Manager that is not affected by this vulnerability.
What versions of Cisco Unified Communications Manager are affected by CVE-2014-0734?
CVE-2014-0734 affects Cisco Unified Communications Manager versions 10.0(1) and earlier, as well as several earlier versions.
Can CVE-2014-0734 be exploited remotely?
Yes, CVE-2014-0734 can be exploited remotely through the Certificate Authority Proxy Function implementation.
Is there a workaround for CVE-2014-0734?
There are no documented workarounds for CVE-2014-0734, and updating to a patched version is recommended.