ID

VAR-201607-0427


CVE

CVE-2016-1446


TITLE

Cisco WebEx Meetings Server In SQL Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2016-003778

DESCRIPTION

SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. This issue is being tracked by Cisco Bug ID CSCuy83200. Cisco WebEx Meetings Server (CWMS) is a set of multi-functional conference solutions including audio, video and Web conference in Cisco's WebEx conference solution

Trust: 1.98

sources: NVD: CVE-2016-1446 // JVNDB: JVNDB-2016-003778 // BID: 91786 // VULHUB: VHN-90265

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetings serverscope:eqversion:2.6.0

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope:eqversion:2.6.1.39

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope:eqversion:2.6

Trust: 1.1

sources: BID: 91786 // JVNDB: JVNDB-2016-003778 // NVD: CVE-2016-1446 // CNNVD: CNNVD-201607-428

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2016-1446
value: HIGH

Trust: 1.8

CNNVD: CNNVD-201607-428
value: MEDIUM

Trust: 0.6

VULHUB: VHN-90265
value: MEDIUM

Trust: 0.1

NVD:
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: TRUE
obtainAllPrivilege: FALSE
obtainUserPrivilege: FALSE
obtainOtherPrivilege: FALSE
userInteractionRequired: FALSE
version: 2.0

Trust: 1.0

NVD: CVE-2016-1446
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-90265
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

NVD:
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.0

NVD: CVE-2016-1446
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-90265 // JVNDB: JVNDB-2016-003778 // NVD: CVE-2016-1446 // CNNVD: CNNVD-201607-428

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.9

sources: VULHUB: VHN-90265 // JVNDB: JVNDB-2016-003778 // NVD: CVE-2016-1446

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201607-428

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-201607-428

CONFIGURATIONS

sources: NVD: CVE-2016-1446

PATCH

title:cisco-sa-20160714-wmsurl:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20160714-wms

Trust: 0.8

title:Cisco WebEx Meetings Server SQL Repair measures for injecting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=62970

Trust: 0.6

sources: JVNDB: JVNDB-2016-003778 // CNNVD: CNNVD-201607-428

EXTERNAL IDS

db:NVDid:CVE-2016-1446

Trust: 2.8

db:BIDid:91786

Trust: 1.4

db:SECTRACKid:1036312

Trust: 1.1

db:JVNDBid:JVNDB-2016-003778

Trust: 0.8

db:CNNVDid:CNNVD-201607-428

Trust: 0.7

db:VULHUBid:VHN-90265

Trust: 0.1

sources: VULHUB: VHN-90265 // BID: 91786 // JVNDB: JVNDB-2016-003778 // NVD: CVE-2016-1446 // CNNVD: CNNVD-201607-428

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20160714-wms

Trust: 2.0

url:http://www.securityfocus.com/bid/91786

Trust: 1.1

url:http://www.securitytracker.com/id/1036312

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-1446

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-1446

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-90265 // BID: 91786 // JVNDB: JVNDB-2016-003778 // NVD: CVE-2016-1446 // CNNVD: CNNVD-201607-428

CREDITS

Cisco

Trust: 0.3

sources: BID: 91786

SOURCES

db:VULHUBid:VHN-90265
db:BIDid:91786
db:JVNDBid:JVNDB-2016-003778
db:NVDid:CVE-2016-1446
db:CNNVDid:CNNVD-201607-428

LAST UPDATE DATE

2023-12-18T14:01:46.760000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-90265date:2017-09-01T00:00:00
db:BIDid:91786date:2016-07-14T00:00:00
db:JVNDBid:JVNDB-2016-003778date:2016-07-21T00:00:00
db:NVDid:CVE-2016-1446date:2017-09-01T01:29:03.787
db:CNNVDid:CNNVD-201607-428date:2016-07-18T00:00:00

SOURCES RELEASE DATE

db:VULHUBid:VHN-90265date:2016-07-15T00:00:00
db:BIDid:91786date:2016-07-14T00:00:00
db:JVNDBid:JVNDB-2016-003778date:2016-07-21T00:00:00
db:NVDid:CVE-2016-1446date:2016-07-15T16:59:01.207
db:CNNVDid:CNNVD-201607-428date:2016-07-18T00:00:00