A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc23892 CSCvc35270 CSCvc35626 CSCvc35630 CSCvc49568. Known Affected Releases: 3.1(1) 2.0(4.0.45B).
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/99214 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038751 | Third Party Advisory VDB Entry |
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piepnm2 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2017-07-04T00:00:00
Updated: 2017-07-06T09:57:01
Reserved: 2017-03-09T00:00:00
Link: CVE-2017-6698
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-07-04T00:29:00.243
Modified: 2017-07-07T16:56:49.723
Link: CVE-2017-6698
JSON object: View
Redhat Information
No data.
CWE