cisco prime-license-manager CVE-2018-15441 is a vulnerability in Cisco Prime License Manager
Published on November 28, 2018

Cisco Prime License Manager SQL Injection Vulnerability
A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted HTTP POST requests that contain malicious SQL statements to an affected application. A successful exploit could allow the attacker to modify and delete arbitrary data in the PLM database or gain shell access with the privileges of the postgres user.

Vendor Advisory NVD

Weakness Type

What is a SQL Injection Vulnerability?

The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE-2018-15441 has been classified to as a SQL Injection vulnerability or weakness.


Products Associated with CVE-2018-15441

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2018-15441 are published in Cisco Prime License Manager:

 

Affected Versions

Cisco Prime License Manager Version n/a is affected by CVE-2018-15441

Exploit Probability

EPSS
0.42%
Percentile
61.73%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.