Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.
| Software | From | Fixed in |
|---|---|---|
| cisco / unified_operations_manager | 2.2 | 2.2.x |
| cisco / unified_operations_manager | 2.0 | 2.0.x |
| cisco / unified_operations_manager | 2.0.1 | 2.0.1.x |
| cisco / unified_operations_manager | - | 8.5.x |
| cisco / unified_operations_manager | 2.0.2 | 2.0.2.x |
| cisco / unified_operations_manager | 1.1 | 1.1.x |
| cisco / unified_operations_manager | 2.3 | 2.3.x |
| cisco / unified_operations_manager | 2.1 | 2.1.x |
| cisco / unified_operations_manager | 8.0 | 8.0.x |
| cisco / unified_operations_manager | 2.0.3 | 2.0.3.x |