Vulnerability Bulletins |
Cisco Secure Access Control System SQL Injection Vulnerability |
|
| Affected software | Cisco |
|
Cisco Secure Access Control System (ACS) prior to version 5.5 patch 8 is vulnerable to a SQL injectionattack in the ACS View reporting interface pages. Asuccessful attack could allow an authenticated, remote attacker to access and modify information such as RADIUS accounting records stored in one of the ACS View databases or to access information in the underlying file system. A previous version of this advisory indicated that a product running version 5.5 patch 7 was not vulnerable; however, More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150211-csacs?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Secure%20Access%20Control%20System%20SQL%20Injection%20Vulnerability |
|






