Lucene search

K
ciscoCiscoCISCO-SA-20150616-CVE-2015-4188
HistoryJun 16, 2015 - 7:35 p.m.

Cisco Prime Collaboration Manager SQL Injection Vulnerability

2015-06-1619:35:05
tools.cisco.com
14

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

49.6%

A vulnerability in the Cisco Prime Collaboration Manager interface could allow an unauthenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries.

The vulnerability is due to a lack of input validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected system. An exploit could allow the attacker to determine the presence of certain values in the database.

Cisco has confirmed the vulnerability and released software updates.

To exploit this vulnerability, the attacker must submit malicious requests to the targeted system, making exploitation more difficult in environments that restrict network access from untrusted sources.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscoprime_collaborationMatchany
OR
ciscoprime_collaborationMatchany
VendorProductVersionCPE
ciscoprime_collaborationanycpe:2.3:a:cisco:prime_collaboration:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

49.6%

Related for CISCO-SA-20150616-CVE-2015-4188