[NEWS] Cisco Unified Communications Manager SQL Injection



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Cisco Unified Communications Manager SQL Injection
------------------------------------------------------------------------


SUMMARY

Cisco Unified Communications Manager is vulnerable to a SQL Injection
attack in the parameter key of the admin and user interface pages. A
successful attack could allow an authenticated attacker to access
information such as usernames and password hashes that are stored in the
database.

Cisco has released free software updates that address this vulnerability.

DETAILS

Vulnerable Systems:
* Cisco Unified Communication Manager 5.0/5.1 versions prior to 5.1(3a)
and 6.0/6.1 versions prior to 6.1(1a)

Immune Systems:
* Cisco CallManager or Unified Communication Manager systems prior to 5.0
are not affected by this vulnerability. No 3.x and 4.x releases are
vulnerable.

Cisco Unified CallManager/Communications Manager (CUCM) is the call
processing component of the Cisco IP telephony solution. This solution
extends enterprise telephony features and functions to packet telephony
network devices such as IP phones, media processing devices, voice-over-IP
(VoIP) gateways, and multimedia applications.

An attacker can trigger this SQL injection vulnerability by entering a
specially crafted value is entered in the key parameter of either the
admin or user interface page. Attacks against this vulnerability are
conducted through the web interface and use the http or https protocol. A
successful attack could terminate a SQL call and force a connection to the
back-end database resulting in the disclosure of potentially sensitive
information such as usernames and password hashes.

Impact
An authenticated attacker may be able to exploit this vulnerability to
extract records from the Cisco Unified Communications Manager database. A
successful attack might retrieve sensitive data such as user names,
passwords hashes, and information from call records. An attacker cannot
use this vulnerability to alter or delete call record information from the
database.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0026>
CVE-2008-0026


ADDITIONAL INFORMATION

The information has been provided by <mailto:psirt@xxxxxxxxx> Cisco
Systems Product Security Incident Response Team.
The original article can be found at:
<http://www.cisco.com/warp/public/707/cisco-sa-20080213-cucmsql.shtml>
http://www.cisco.com/warp/public/707/cisco-sa-20080213-cucmsql.shtml



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NEWS] Cisco Unified Communications Manager CAPF Denial of Service Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Cisco Unified Communications Manager CAPF Denial of Service Vulnerability ... The CAPF service is disabled by default. ...
    (Securiteam)
  • [UNIX] Hewlett Packard HP-UX Remote pfs_mountd.rpc Buffer Overflow Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Hewlett Packard HP-UX Remote pfs_mountd.rpc Buffer Overflow Vulnerability ... the attack is functional over UDP, thus allowing an attacker to completely ... 10/25/2004 Initial vendor notification ...
    (Securiteam)
  • [NT] Adobe LiveCycle Workflow XSS Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Adobe LiveCycle Workflow XSS Vulnerability ... vulnerability which is susceptible to a cross site scripting attack. ... Input passed to the URL of the web management login page is not properly ...
    (Securiteam)
  • [UNIX] Trend Micro VirusWall Buffer Overflow in VSAPI Library
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... buffer overflow vulnerability in VSAPI library allows arbitrary code ... is called "vscan" which is set suid root by default. ... permissions and thus granted all local users the privilege to execute the ...
    (Securiteam)
  • [UNIX] SCO Multiple Local Buffer Overflow
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Local exploitation of a buffer overflow vulnerability in the ppp binary, ... allows attackers to gain root privileges. ...
    (Securiteam)