VDB

CVE-2022-20786

CVE-2022-20786 PUBLISHED CVSS 5.400000095367432 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system.

EPSS 0.84% · 56.6th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.84%
56.6th percentile

Affected Products

VendorProductVersions
ciscounified_communications_manager_im_and_presence_service11.5\(1\), 12.5\(1\), 14.0
CiscoCisco Unified Communications Manager IM and Presence Servicen/a

Timeline

  • Apr 21, 2022 CVE Published
  • Apr 22, 2022 EPSS Score
  • Jun 12, 2022 EPSS Score
  • Aug 2, 2022 EPSS Score
  • Sep 22, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
  • Jan 1, 2023 EPSS Score
  • Feb 21, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Jun 2, 2023 EPSS Score
  • Jul 23, 2023 EPSS Score
  • Sep 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›