CVE-2017-6698 – Cisco Prime Infrastructure 3.1.6 XXE Injection / XSS / LFD / SQL Injection
https://notcve.org/view.php?id=CVE-2017-6698
A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc23892 CSCvc35270 CSCvc35626 CSCvc35630 CSCvc49568. Known Affected Releases: 3.1(1) 2.0(4.0.45B). Una vulnerabilidad en la interfaz de base de datos SQL de Prime Infrastructure (PI) y Evolved Programmable Network Manager (EPNM) de Cisco, podría permitir a un atacante remoto identificado impactar la confidencialidad y la integridad de la aplicación ejecutando consultas SQL arbitrarias, también se conoce como Inyección SQL. Más información: CSCvc23892 CSCvc35270 CSCvc35626 CSCvc35630 CSCvc49568. • http://www.securityfocus.com/bid/99214 http://www.securitytracker.com/id/1038751 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piepnm2 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2017-3884
https://notcve.org/view.php?id=CVE-2017-3884
A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data. The attacker does not need administrator credentials and could use this information to conduct additional reconnaissance attacks. More Information: CSCvc60031 (Fixed) CSCvc60041 (Fixed) CSCvc60095 (Open) CSCvc60102 (Open). Known Affected Releases: 2.2 2.2(3) 3.0 3.1(0.0) 3.1(0.128) 3.1(4.0) 3.1(5.0) 3.2(0.0) 2.0(4.0.45D). Una vulnerabilidad en la interfaz web de Cisco Prime Infrastructure y del administrador Evolved Programmable Network de Cisco (EPN) podría permitir a un atacante remoto autenticado acceder a datos confidenciales. • http://www.securityfocus.com/bid/97470 http://www.securitytracker.com/id/1038189 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cpi • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-3869
https://notcve.org/view.php?id=CVE-2017-3869
An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Information: CSCuy36192. Known Affected Releases: 3.1(1) 3.1(1). Una vulnerabilidad de API Credentials Management en las API de Cisco Prime Infrastructure podría permitir a un atacante remoto autenticado acceder a una API que debería estar restringida a un usuario privilegiado. • http://www.securityfocus.com/bid/96931 http://www.securitytracker.com/id/1038048 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-cpi •
CVE-2016-6443
https://notcve.org/view.php?id=CVE-2016-6443
A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1.2(400), 2.0(1.0.34A). Una vulnerabilidad en Cisco Prime Infrastructure y en la interfaz de la base de datos SQL de Evolved Programmable Network Manager podría permitir a un atacante remoto autenticado impactar la confidencialidad del sistema ejecutando un subconjunto de consultas SQL arbitrarias que pueden provocar inestabilidad en el producto. Más información: CSCva27038, CSCva28335. • http://www.securityfocus.com/bid/93522 http://www.securitytracker.com/id/1037006 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-prime • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2016-1442
https://notcve.org/view.php?id=CVE-2016-1442
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280. La interfáz de web administrativa en Cisco Prime Infrastructure (PI) en versiones anteriores a 3.1.1 permite a usuarios remotos autenticados ejecutar comandos arbitrarios a través de valores de campo manipulados, también conocido como Bug ID CSCuy96280. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160706-pi http://www.securitytracker.com/id/1036238 • CWE-20: Improper Input Validation •