cisco-sa-20171129-prime
Cisco Prime Service Catalog SQL Injection Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied input that is used in SQL queries. An attacker could exploit this vulnerability by sending a crafted SQL statement to an affected system. Successful exploitation could allow the attacker to read entries in some database tables. There are no workarounds that address this vulnerability.
| Product | CVE |
|---|---|
| Cisco Prime Service Catalog | CVE-2017-12364 |