SQL injection in Cisco SD-WAN and Cisco vManage Network Management Software - CVE-2019-16012
Published: March 19, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the web UI. A remote authenticated attacker can send a specially crafted request to the affected application and modify values on, or return values from, the underlying database as well as the operating system.
Affected software
Cisco vManage Network Management Software