CVE-2013-3437
Cisco Unified Operations Manager - Authenticated SQL Injection via Entry Field
Title source: llmDescription
SQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary SQL commands via an entry field, aka Bug ID CSCud80179.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/95472
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=30153
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3437
Scores
EPSS
0.0103
EPSS Percentile
60.1%
Details
CWE
CWE-89
Status
published
Products (1)
cisco/unified_operations_manager
Published
Jul 23, 2013
Tracked Since
Feb 18, 2026