SQL Injection Vulnerability in Cisco Secure Access Control Server
CVE-2015-6345

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
30 October 2015

What is CVE-2015-6345?

A SQL injection vulnerability exists in the Solution Engine of Cisco Secure Access Control Server, specifically in version 5.7(0.15). This security issue enables remote authenticated users to execute arbitrary SQL commands through specially crafted URLs. The exploitation of this vulnerability can lead to unauthorized data access or alteration within the affected system. Users are advised to apply patches and monitor their systems for suspicious activity to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2015-6345 : SQL Injection Vulnerability in Cisco Secure Access Control Server