Lucene search

K
nvd[email protected]NVD:CVE-2017-12364
HistoryNov 30, 2017 - 9:29 a.m.

CVE-2017-12364

2017-11-3009:29:01
CWE-89
web.nvd.nist.gov
4

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

42.0%

A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied input that is used in SQL queries. An attacker could exploit this vulnerability by sending a crafted SQL statement to an affected system. Successful exploitation could allow the attacker to read entries in some database tables. Cisco Bug IDs: CSCvg30333.

Affected configurations

Nvd
Node
ciscoprime_service_catalogMatch11.1.1
OR
ciscoprime_service_catalogMatch12.0
OR
ciscoprime_service_catalogMatch12.1
VendorProductVersionCPE
ciscoprime_service_catalog11.1.1cpe:2.3:a:cisco:prime_service_catalog:11.1.1:*:*:*:*:*:*:*
ciscoprime_service_catalog12.0cpe:2.3:a:cisco:prime_service_catalog:12.0:*:*:*:*:*:*:*
ciscoprime_service_catalog12.1cpe:2.3:a:cisco:prime_service_catalog:12.1:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

42.0%

Related for NVD:CVE-2017-12364