A vulnerability in the web framework of the Cisco Firepower Management Center could allow an authenticated, remote attacker to perform SQL injection on the affected device. The vulnerability is due to a lack of input validation. An attacker could exploit this vulnerability by sending a crafted SQL request to the affected web page. An exploit could allow the attacker to modify the database used by the Firepower management Center. There are no workarounds that address this vulnerability. No other Cisco products are currently known to be affected by this vulnerability. Cisco provides information about fixed software in Cisco Bug Search Tool.”]
Source: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-fpmc

