Vulnslist

find the latest Cisco vulnerabilities

Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing

cisco-sa-20121031-mp · High · Published · Updated

Cisco Unified MeetingPlace Web Conferencing is affected by two vulnerabilities: Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability Cisco Unified MeetingPlace Web Conferencing Buffer Overrun Vulnerability Exploitation of the Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability may allow an unauthenticated, remote attacker to send Structured Query Language (SQL) commands to manipulate the MeetingPlace database stores information about server configuration, meetings, and users. These commands may be used to create, delete, or alter some of the information in the Cisco Unified MeetingPlace Web Conferencing database. Exploitation of the Cisco Unified MeetingPlace Web Conferencing Buffer Overrun Vulnerability may allow an unauthenticated, remote attacker to create a buffer overrun condition that may cause the Web Conferencing server to become unresponsive. Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mp

Workarounds

No workarounds are available to mitigate these vulnerabilities.

CVEsCVE-2012-0337, CVE-2012-5416
Cisco Bug IDsCSCtx08939, CSCua66341
CVSS ScoreBase 8.5
Base 8.5 AV:N/AC:L/Au:N/C:N/I:P/A:C/E:F/RL:OF/RC:C
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco Unified MeetingPlace Web Conferencing

Related Products

Product CVE Evidence
Cisco Unified MeetingPlace CVE-2012-5416 Cisco OpenVuln
Cisco Unified MeetingPlace Web Conferencing CVE-2012-5416 Cisco OpenVuln
Cisco Unified MeetingPlace CVE-2012-0337 Cisco OpenVuln
Cisco Unified MeetingPlace Web Conferencing CVE-2012-0337 Cisco OpenVuln