Known vulnerabilities in Unified Communications Manager (CallManager) - page 2

Software CPE: cpe:2.3:a:cisco_systems:unified_communications_manager_callmanager:*:*:*:*:*:*:*:*
Total vulnerabilities: 48
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Unified Communications Manager (CallManager) Unified Communications Manager (CallManager) is affected by 48 known vulnerabilities: 1 high, 5 medium, 42 low Critical High Medium Low

Vulnerabilities (48)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU14166 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0411
CWE-79 Low
No
No
12.0.1.22900.3, 12.5.0.97000.311, 12.5.0.98000.321, 12.5.0.98000.815, 12.5.0.98000.935 01.08.2018 SB2018080202
#VU13412 - Cross-Site Request Forgery (CSRF)
CVE-2018-0363
CWE-352 Low
No
No
11.5.1.15900.19, 11.5.1.15900.23, 12.5.0.98000.823, 12.5.0.98000.849 20.06.2018 SB2018062111
#VU13205 - Improper Link Resolution Before File Access ('Link Following')
CVE-2018-0355
CWE-59 Low
No
No
11.5.1.15900.8, 12.5.0.98000.666, 12.5.0.98000.667 07.06.2018 SB2018060702
#VU13204 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0340
CWE-79 Low
No
No
11.5.1.15900.8, 11.5.1.15900.15, 11.5.1.15900.16, 12.5.0.97000.265, 12.5.0.98000.265, 12.5.0.98000.653, 12.5.0.98000.779 06.06.2018 SB2018060702
#VU12795 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0328
CWE-79 Low
No
No
- 16.05.2018 SB2018051719
#VU12061 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0267
CWE-200 Low
No
No
- 18.04.2018 SB2018042404
#VU12062 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0266
CWE-200 Low
No
No
- 18.04.2018 SB2018042404
#VU10692 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0206
CWE-79 Low
No
No
- 21.02.2018 SB2018022212
#VU10396 - Improper input validation
CVE-2018-0135
CWE-20 Low
No
No
- 07.02.2018 SB2018020802
#VU10398 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0198
CWE-200 Low
No
No
- 07.02.2018 SB2018020802
#VU10399 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-0120
CWE-89 Low
No
No
- 07.02.2018 SB2018020802
#VU10110 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0105
CWE-200 Low
No
No
- 19.01.2018 SB2018011904
#VU9954 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0118
CWE-79 Low
No
No
- 10.01.2018 SB2018011103
#VU9468 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-12357
CWE-79 Low
No
No
- 29.11.2017 SB2017113010
#VU9387 - Improper Authentication
CVE-2017-12337
CWE-287 High
No
No
- 21.11.2017 SB2017112115
SB2017112116
SB2017112117
and 5 more
#VU9382 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-12302
CWE-89 Low
No
No
- 16.11.2017 SB2017112109
#VU8709 - Improper Link Resolution Before File Access ('Link Following')
CVE-2017-12258
CWE-59 Low
No
No
- 05.10.2017 SB2017100510
#VU8158 - Improper input validation
CVE-2017-6791
CWE-20 Low
No
No
- 07.09.2017 SB2017090716
#VU7977 - Improper input validation
CVE-2017-6785
CWE-20 Low
No
No
- 16.08.2017 SB2017081706
#VU7674 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-6757
CWE-89 Low
No
No
- 03.08.2017 SB2017080305


Showing elements 21 - 40 out of 48