Multiple Vulnerabilities in Cisco Unified Communications Manager

Related Vulnerabilities: CVE-2011-1604   CVE-2011-1605   CVE-2011-1606   CVE-2011-1607   CVE-2011-1609   CVE-2011-1610  

Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three (3) denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two (2) SQL injection vulnerabilities Cisco has released free software updates for affected Cisco Unified Communications Manager versions to address the vulnerabilities. A workaround exists only for the SIP DoS vulnerabilities. This advisory is posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110427-cucm.