CVE-2016-1437
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160621-pcd
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | prime_collaboration_deployment | 10.5.0 | |
| cisco | prime_collaboration_deployment | 10.5.1 | |
| cisco | prime_collaboration_deployment | 11.0_base | |
| cisco | prime_collaboration_deployment | 11.5.0 | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.