CVE-2015-6331: SQL Injection
Published Oct 12, 2015
·Updated
SQL injection vulnerability in the web framework in Cisco Prime Collaboration Assurance 10.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCus39887.
Affected Software
1 affected component
cisco Prime Collaboration Assurance=10.5.1
Event History
Oct 12, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6331?
CVE-2015-6331 has a high severity rating due to the potential for remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2015-6331?
To fix CVE-2015-6331, upgrade to the latest version of Cisco Prime Collaboration Assurance that addresses this vulnerability.
3
What software is affected by CVE-2015-6331?
CVE-2015-6331 affects Cisco Prime Collaboration Assurance version 10.5(1).
4
Who can exploit CVE-2015-6331?
CVE-2015-6331 can be exploited by remote authenticated users with access to the affected web application.
5
What type of vulnerability is CVE-2015-6331?
CVE-2015-6331 is classified as an SQL injection vulnerability, which allows unauthorized SQL execution.