CVE-2014-2652: SQL Injection
Published Mar 19, 2018
·Updated
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
Unify Openscape Deployment Service<6.0
Unify Openscape Deployment Service=7.0
Event History
Mar 19, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2014-2652?
CVE-2014-2652 is a SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3.
2
How severe is CVE-2014-2652?
CVE-2014-2652 has a severity rating of 9.8 (critical).
3
How does CVE-2014-2652 affect OpenScape Deployment Service?
CVE-2014-2652 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in OpenScape Deployment Service.
4
What is the affected version of OpenScape Deployment Service?
OpenScape Deployment Service versions before 6.x and 7.x before R1.11.3 are affected by CVE-2014-2652.
5
How can I fix CVE-2014-2652?
To fix CVE-2014-2652, it is recommended to upgrade OpenScape Deployment Service to version 6.x or 7.x R1.11.3 or later.