First published: Fri Oct 30 2015(Updated: )
SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuw50843.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Service Catalog | =11.0_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6350 is classified as a high severity vulnerability due to the potential for remote authenticated users to execute arbitrary SQL commands.
To mitigate CVE-2015-6350, upgrade to a patched version of Cisco Prime Service Catalog that addresses this SQL injection vulnerability.
CVE-2015-6350 affects Cisco Prime Service Catalog version 11.0_base.
CVE-2015-6350 can be exploited by remote authenticated users with access to the affected web framework.
CVE-2015-6350 is an SQL injection vulnerability, allowing attackers to manipulate database queries.