CVE-2015-0715: SQL Injection
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0715?
CVE-2015-0715 has a moderate severity level due to the potential for unauthorized SQL command execution.
How do I fix CVE-2015-0715?
To fix CVE-2015-0715, it is recommended to upgrade Cisco Unified Communications Manager to a version that addresses this vulnerability.
Who is affected by CVE-2015-0715?
CVE-2015-0715 affects remote authenticated users of Cisco Unified Communications Manager version 11.0(0.98000.225).
What type of vulnerability is CVE-2015-0715?
CVE-2015-0715 is classified as an SQL injection vulnerability that can be exploited through the administrative web interface.
Can CVE-2015-0715 lead to data leakage?
Yes, an exploit of CVE-2015-0715 can potentially lead to data leakage by allowing the execution of arbitrary SQL commands.