CVE-2019-15972 is a high-severity SQL injection vulnerability affecting the web-based management interface of Cisco Unified Communications Manager. An authenticated, remote attacker can exploit this flaw by sending malicious requests due to improper validation of SQL values. Successful exploitation could lead to modification or retrieval of data from the underlying database, with a CVSS score of 8.8 (High). While no public exploit code or active exploitation is reported, and community discussion is minimal, the vulnerability presents a significant risk to affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5\(2.10000.5\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:10.5\(2.10000.5\):*:*:*:*:*:*:* | ||
11.5\(1.10000.6\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.10000.6\):*:*:*:*:*:*:* | ||
12.0\(1.10000.10\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.0\(1.10000.10\):*:*:*:*:*:*:* | ||
12.5\(1.10000.22\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1.10000.22\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.