Apache · Apache Http Server · CVE-2011-1610
**Name of the Vulnerable Software and Affected Versions**
Cisco Unified Communications Manager versions 6.x through 6.1(5)su2, 7.x through 7.1(5)su3, 8.0 through 8.0(3a)su1, and 8.5 through 8.5(0)su0
**Description**
The issue allows remote attackers to execute arbitrary SQL commands via the `f`, `l`, or `n` parameter in the xmldirectorylist.jsp file of the embedded Apache HTTP Server component.
**Recommendations**
For versions 6.x through 6.1(5)su2, update to version 6.1(5)su3 or later.
For versions 7.x through 7.1(5)su3, update to version 7.1(5)su4 or later.
For versions 8.0 through 8.0(3a)su1, update to version 8.0(3a)su2 or later.
For versions 8.5 through 8.5(0)su0, update to version 8.5(1)su1 or later.