← Back

CVE-2011-4487

nvd nist
Published: Mar 1, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a crafted SCCP registration, aka Bug ID CSCtu73538.

Affected (93)

7 products
Unified Communications Manager
Business Edition 3000 Software
Business Edition 3000
Business Edition 5000 Software
Business Edition 5000
Business Edition 6000 Software
Business Edition 6000
Configuration A
22 vulnerable
Configuration B
27 vulnerable
Configuration C
11 vulnerable
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 8.5
Version 8.5(1)
Version 8.5(1)su1
Version 8.5(1)su2
Version 8.5(1)su3
Configuration E
5 vulnerable
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 8.6.2
Version 8.6(1)
Version 8.6(1a)
Version 8.6(2a)
All versions
Configuration G
8 vulnerable
Configuration H
10 vulnerable

Timeline

No history available yet.