First published: Mon Aug 11 2014(Updated: )
SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Connection | =9.1\(1\) | |
Cisco Unity Connection | =9.1\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3336 has a high severity rating due to the potential for unauthorized SQL command execution.
To address CVE-2014-3336, upgrade to Cisco Unity Connection version 9.1(3) or later.
CVE-2014-3336 affects users of Cisco Unity Connection versions 9.1(1) and 9.1(2) that are remote authenticated.
CVE-2014-3336 is classified as an SQL injection vulnerability.
Yes, CVE-2014-3336 can be exploited by remote authenticated users.