#VU26221 SQL injection in Cisco SD-WAN and Cisco vManage Network Management Software - CVE-2019-16012
Published: March 19, 2020
Cisco SD-WAN
Cisco vManage Network Management Software
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the web UI. A remote authenticated attacker can send a specially crafted request to the affected application and modify values on, or return values from, the underlying database as well as the operating system.