SQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary SQL commands via an entry field, aka Bug ID CSCud80179.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3437 | Vendor Advisory |
http://osvdb.org/95472 | |
http://tools.cisco.com/security/center/viewAlert.x?alertId=30153 | Vendor Advisory |
Configurations
Information
Published : 2013-07-23 04:03
Updated : 2016-09-16 11:03
NVD link : CVE-2013-3437
Mitre link : CVE-2013-3437
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
cisco
- unified_operations_manager