
CVE-2018-0124
https://notcve.org/view.php?id=CVE-2018-0124
22 Feb 2018 — A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is due to insecure key generation during application configuration. An attacker could exploit this vulnerability by using a known insecure key value to bypass security protections by sending arbitrary requests using the insecure key to a targeted application. An exploit could allow the attacker t... • http://www.securityfocus.com/bid/103114 • CWE-320: Key Management Errors •

CVE-2017-6670
https://notcve.org/view.php?id=CVE-2017-6670
13 Jun 2017 — A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8.1(7)ER1. Una vulnerabilidad en la GUI basada en web de Cisco Unified Communications Domain Manager, podría permitir a un atacante remoto no autenticado redireccionar a un usuario hacia una página web maliciosa, también se conoce como un problema de Re... • http://www.securityfocus.com/bid/98946 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-6668
https://notcve.org/view.php?id=CVE-2017-6668
13 Jun 2017 — Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1. Vulnerabilidades en la GUI basada en web de Cisco Unified Communications Domain Manager (CUCDM), podrían permitir a un atacante autenticado y remoto afectar la confidencialidad del sistema mediante ... • http://www.securityfocus.com/bid/98947 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-0682
https://notcve.org/view.php?id=CVE-2015-0682
03 Apr 2015 — Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168. Cisco Unified Communications Domain Manager 8.1(4) permite a usuarios remotos autenticados ejecutar código arbitrario mediante la visita a una 'página obsoleta,' también conocido como Bug ID CSCup90168. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38113 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-0683
https://notcve.org/view.php?id=CVE-2015-0683
03 Apr 2015 — Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via a file-inclusion attack, aka Bug ID CSCup94744. Cisco Unified Communications Domain Manager 8.1(4) permite a usuarios remotos autenticados obtener información sensible a través de un ataque de inclusión de ficheros, también conocido como Bug ID CSCup94744. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38118 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-0684
https://notcve.org/view.php?id=CVE-2015-0684
03 Apr 2015 — SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515. Vulnerabilidad de inyección SQL en el componente Image Management en Cisco Unified Communications Domain Manager 8.1(4) permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de vectores no especificados, también conocido como Bug ID CSCuq52515. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38114 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2014-3337
https://notcve.org/view.php?id=CVE-2014-3337
12 Aug 2014 — The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428. La implementación SIP en Cisco Unified Communications Manager (CM) 8.6(.2) y anteriores permite a usuarios remotos autenticados causar una denegación de servicio (caída del proceso) a través de un mensaje SIP manipulado que no se... • http://secunia.com/advisories/60088 • CWE-20: Improper Input Validation •

CVE-2014-3320
https://notcve.org/view.php?id=CVE-2014-3320
18 Jul 2014 — Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Communications Domain Manager (CDM) 8.1(.4) and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted URLs for unspecified scripts, aka Bug ID CSCuo48835. Múltiples vulnerabilidades de redirección abierta en la interfaz de web admin en el Framework web en Cisco Unified Communications Domain Manager (CDM) 8.1(.4) y anteriores permiten a atacantes r... • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3320 •

CVE-2014-3280
https://notcve.org/view.php?id=CVE-2014-3280
03 Jun 2014 — The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116. El Framework web en VOSS en Cisco Unified Communications Domain Manager (CDM) 9.0(.1) y anteriores no implementa debidamente control de acceso, lo que permite a usuarios remotos autenti... • http://secunia.com/advisories/58400 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-3277
https://notcve.org/view.php?id=CVE-2014-3277
29 May 2014 — The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive user and group information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum77005. La interfaz gráfica de usuario (GUI) Administration en el Framework web en VOSS en Cisco Unified Communications Domain Manager (CDM) 9.0(.1) y anteriores no ... • http://secunia.com/advisories/58400 • CWE-287: Improper Authentication •