cisco-sa-20171129-prime

Cisco Prime Service Catalog SQL Injection Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied input that is used in SQL queries. An attacker could exploit this vulnerability by sending a crafted SQL statement to an affected system. Successful exploitation could allow the attacker to read entries in some database tables. There are no workarounds that address this vulnerability.