ID

VAR-201711-0375


CVE

CVE-2017-12364


TITLE

Cisco Prime Service Catalog In SQL Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-010413

DESCRIPTION

A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied input that is used in SQL queries. An attacker could exploit this vulnerability by sending a crafted SQL statement to an affected system. Successful exploitation could allow the attacker to read entries in some database tables. Cisco Bug IDs: CSCvg30333. Vendors have confirmed this vulnerability Bug ID CSCvg30333 It is released as.Information may be obtained and information may be altered. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The solution supports automated ordering of a unified service catalog of computing, networking, storage, and other data center resources

Trust: 1.98

sources: NVD: CVE-2017-12364 // JVNDB: JVNDB-2017-010413 // BID: 102004 // VULHUB: VHN-102879

AFFECTED PRODUCTS

vendor:ciscomodel:prime service catalogscope:eqversion:12.1

Trust: 1.9

vendor:ciscomodel:prime service catalogscope:eqversion:12.0

Trust: 1.9

vendor:ciscomodel:prime service catalogscope:eqversion:11.1.1

Trust: 1.9

vendor:ciscomodel:prime service catalogscope: - version: -

Trust: 0.8

sources: BID: 102004 // JVNDB: JVNDB-2017-010413 // CNNVD: CNNVD-201711-1202 // NVD: CVE-2017-12364

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-12364
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-12364
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201711-1202
value: MEDIUM

Trust: 0.6

VULHUB: VHN-102879
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-12364
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-102879
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-12364
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.5
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-102879 // JVNDB: JVNDB-2017-010413 // CNNVD: CNNVD-201711-1202 // NVD: CVE-2017-12364

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.9

sources: VULHUB: VHN-102879 // JVNDB: JVNDB-2017-010413 // NVD: CVE-2017-12364

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201711-1202

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-201711-1202

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-010413

PATCH

title:cisco-sa-20171129-primeurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-prime

Trust: 0.8

title:Cisco Prime Service Catalog SQL Repair measures for injecting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76821

Trust: 0.6

sources: JVNDB: JVNDB-2017-010413 // CNNVD: CNNVD-201711-1202

EXTERNAL IDS

db:NVDid:CVE-2017-12364

Trust: 2.8

db:BIDid:102004

Trust: 2.0

db:SECTRACKid:1039926

Trust: 1.7

db:JVNDBid:JVNDB-2017-010413

Trust: 0.8

db:CNNVDid:CNNVD-201711-1202

Trust: 0.7

db:VULHUBid:VHN-102879

Trust: 0.1

sources: VULHUB: VHN-102879 // BID: 102004 // JVNDB: JVNDB-2017-010413 // CNNVD: CNNVD-201711-1202 // NVD: CVE-2017-12364

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20171129-prime

Trust: 2.0

url:http://www.securityfocus.com/bid/102004

Trust: 1.7

url:http://www.securitytracker.com/id/1039926

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-12364

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-12364

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-102879 // BID: 102004 // JVNDB: JVNDB-2017-010413 // CNNVD: CNNVD-201711-1202 // NVD: CVE-2017-12364

CREDITS

Cisco

Trust: 0.3

sources: BID: 102004

SOURCES

db:VULHUBid:VHN-102879
db:BIDid:102004
db:JVNDBid:JVNDB-2017-010413
db:CNNVDid:CNNVD-201711-1202
db:NVDid:CVE-2017-12364

LAST UPDATE DATE

2024-11-23T22:56:03.896000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-102879date:2019-10-09T00:00:00
db:BIDid:102004date:2017-12-19T22:37:00
db:JVNDBid:JVNDB-2017-010413date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201711-1202date:2019-10-17T00:00:00
db:NVDid:CVE-2017-12364date:2024-11-21T03:09:23.453

SOURCES RELEASE DATE

db:VULHUBid:VHN-102879date:2017-11-30T00:00:00
db:BIDid:102004date:2017-11-29T00:00:00
db:JVNDBid:JVNDB-2017-010413date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201711-1202date:2017-12-01T00:00:00
db:NVDid:CVE-2017-12364date:2017-11-30T09:29:01.447