CVE-2016-6443

A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1.2(400), 2.0(1.0.34A).

Date published : 2016-10-27

http://www.securityfocus.com/bid/93522

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-prime