PT-2015-3184 · Cisco · Cisco Identity Services Engine
Publicado
2015-07-14
·
Atualizado
2016-12-28
·
CVE-2015-4268
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine versions 1.2(1.198) and 1.3(0.876)
Description
The issue exists due to insufficient protection of the web page structure, allowing for the exploitation of multiple cross-site scripting (XSS) vulnerabilities. This can enable a remote attacker to inject arbitrary web script or HTML code via
GET or POST requests.Recommendations
For version 1.2(1.198), update to a version that includes the fix for Bug ID CSCus16052.
For version 1.3(0.876), update to a version that includes the fix for Bug ID CSCus16052.
As a temporary workaround, consider restricting access to the Infra Admin UI to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Identity Services Engine