Vulnerability Details CVE-2021-1355
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.4%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2021-1355
-
cpe:2.3:a:cisco:unified_communications_manager:-
-
cpe:2.3:a:cisco:unified_communications_manager:10.0
-
cpe:2.3:a:cisco:unified_communications_manager:10.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:10.0(1.10000.24)
-
cpe:2.3:a:cisco:unified_communications_manager:10.0_base
-
cpe:2.3:a:cisco:unified_communications_manager:10.5
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(0.98000.88)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(1.98991.13)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su1
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su10
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su2
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su2a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su3
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su3a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su4
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su4a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su5
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su6
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su6a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su7
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su8
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su9
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2.10000.5)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2.12901.1)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2.13900.9)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2.14076.1)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(3.10000.9)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5_base
-
cpe:2.3:a:cisco:unified_communications_manager:11.0
-
cpe:2.3:a:cisco:unified_communications_manager:11.0(0.98000.225)
-
cpe:2.3:a:cisco:unified_communications_manager:11.0(1.10000.10)
-
cpe:2.3:a:cisco:unified_communications_manager:11.0(1.24075.1)
-
cpe:2.3:a:cisco:unified_communications_manager:11.0(1a)su4
-
cpe:2.3:a:cisco:unified_communications_manager:11.5
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(0.98000.480)
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(0.98000.486)
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(0.99838.4)
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su2
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su3
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su4
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su5
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su7
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su8
-
cpe:2.3:a:cisco:unified_communications_manager:12.0
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(0.98000.452)
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(0.99000.9)
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(0.99999.2)
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(1)su2
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(1)su3
-
cpe:2.3:a:cisco:unified_communications_manager:12.5
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su2
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su3
-
cpe:2.3:a:cisco:unified_communications_manager:3.3(5)
-
cpe:2.3:a:cisco:unified_communications_manager:3.3(5)sr1
-
cpe:2.3:a:cisco:unified_communications_manager:3.3(5)sr2a
-
cpe:2.3:a:cisco:unified_communications_manager:4.1
-
cpe:2.3:a:cisco:unified_communications_manager:4.1(3)
-
cpe:2.3:a:cisco:unified_communications_manager:4.1(3)sr1
-
cpe:2.3:a:cisco:unified_communications_manager:4.1(3)sr2
-
cpe:2.3:a:cisco:unified_communications_manager:4.1(3)sr3
-
cpe:2.3:a:cisco:unified_communications_manager:4.1(3)sr4
-
cpe:2.3:a:cisco:unified_communications_manager:4.1(3)sr6
-
cpe:2.3:a:cisco:unified_communications_manager:4.1(3)sr7
-
cpe:2.3:a:cisco:unified_communications_manager:4.2
-
cpe:2.3:a:cisco:unified_communications_manager:4.2(3)sr3
-
cpe:2.3:a:cisco:unified_communications_manager:4.2(3)sr4
-
cpe:2.3:a:cisco:unified_communications_manager:4.2.1
-
cpe:2.3:a:cisco:unified_communications_manager:4.2.2
-
cpe:2.3:a:cisco:unified_communications_manager:4.2.3
-
cpe:2.3:a:cisco:unified_communications_manager:4.2.3sr1
-
cpe:2.3:a:cisco:unified_communications_manager:4.2.3sr2
-
cpe:2.3:a:cisco:unified_communications_manager:4.2.3sr2b
-
cpe:2.3:a:cisco:unified_communications_manager:4.3
-
cpe:2.3:a:cisco:unified_communications_manager:4.3(1)
-
cpe:2.3:a:cisco:unified_communications_manager:4.3(2)
-
cpe:2.3:a:cisco:unified_communications_manager:4.3(2)sr1
-
cpe:2.3:a:cisco:unified_communications_manager:5.0
-
cpe:2.3:a:cisco:unified_communications_manager:5.1
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(1)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(1b)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(1c)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(2)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(2b)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(3)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(3a)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(3c)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(3d)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(3e)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1(3g)
-
cpe:2.3:a:cisco:unified_communications_manager:5.1.2
-
cpe:2.3:a:cisco:unified_communications_manager:6.0
-
cpe:2.3:a:cisco:unified_communications_manager:6.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:6.0(1a)
-
cpe:2.3:a:cisco:unified_communications_manager:6.0(1b)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(1)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(1a)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(1b)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(2)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(2)su1
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(2)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(3)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(3a)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(3b)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(3b)su1
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(4)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(4)su1
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(4a)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(4a)su2
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(4b)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(5)
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(5)su1
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(5)su2
-
cpe:2.3:a:cisco:unified_communications_manager:6.1(5)su3
-
cpe:2.3:a:cisco:unified_communications_manager:7.0
-
cpe:2.3:a:cisco:unified_communications_manager:7.0(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.0(1)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:7.0(2)
-
cpe:2.3:a:cisco:unified_communications_manager:7.0(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:7.0(2a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.0(2a)su2
-
cpe:2.3:a:cisco:unified_communications_manager:7.1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(1)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2b)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(2b)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3a)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3a)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3b)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3b)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(3b)su2
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5a)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su1
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su1a
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su2
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su3
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su4
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su5
-
cpe:2.3:a:cisco:unified_communications_manager:7.1(5b)su6
-
cpe:2.3:a:cisco:unified_communications_manager:8.0
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2b)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2c)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(2c)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)su2
-
cpe:2.3:a:cisco:unified_communications_manager:8.0(3a)su3
-
cpe:2.3:a:cisco:unified_communications_manager:8.0_base
-
cpe:2.3:a:cisco:unified_communications_manager:8.5
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su2
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su3
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su4
-
cpe:2.3:a:cisco:unified_communications_manager:8.5(1)su5
-
cpe:2.3:a:cisco:unified_communications_manager:8.5.1
-
cpe:2.3:a:cisco:unified_communications_manager:8.5_base
-
cpe:2.3:a:cisco:unified_communications_manager:8.6
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(1)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(1a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)su1
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)su2
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(2a)su3
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(3)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6(4)
-
cpe:2.3:a:cisco:unified_communications_manager:8.6.1
-
cpe:2.3:a:cisco:unified_communications_manager:8.6.2
-
cpe:2.3:a:cisco:unified_communications_manager:8.6_base
-
cpe:2.3:a:cisco:unified_communications_manager:9.0
-
cpe:2.3:a:cisco:unified_communications_manager:9.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1
-
cpe:2.3:a:cisco:unified_communications_manager:9.1(1)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1(1a)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1(2)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1(2.10000.28)
-
cpe:2.3:a:cisco:unified_communications_manager:9.1.1(a)
-
cpe:2.3:a:cisco:unified_communications_manager:9.9(9)st1.9
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:-
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5(2)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5(2)su10
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5(1)su8
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.0
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:9.0(1)