First published: Fri Jun 26 2015(Updated: )
SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager IM and Presence | =9.1\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4222 is considered a medium severity vulnerability due to its potential for exploitation via SQL injection.
To fix CVE-2015-4222, users should apply the security updates provided by Cisco for Cisco Unified Communications Manager IM and Presence Service version 9.1(1).
CVE-2015-4222 affects remote authenticated users of Cisco Unified Communications Manager IM and Presence Service version 9.1(1).
Attackers can execute arbitrary SQL commands on the affected system due to the SQL injection vulnerability in CVE-2015-4222.
Currently, there are no known effective workarounds for mitigating CVE-2015-4222 other than applying the security updates.