PT-2015-3184 · Cisco · Cisco Identity Services Engine

Publicado

2015-07-14

·

Atualizado

2016-12-28

·

CVE-2015-4268

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine versions 1.2(1.198) and 1.3(0.876)
Description The issue exists due to insufficient protection of the web page structure, allowing for the exploitation of multiple cross-site scripting (XSS) vulnerabilities. This can enable a remote attacker to inject arbitrary web script or HTML code via GET or POST requests.
Recommendations For version 1.2(1.198), update to a version that includes the fix for Bug ID CSCus16052. For version 1.3(0.876), update to a version that includes the fix for Bug ID CSCus16052. As a temporary workaround, consider restricting access to the Infra Admin UI to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00554
CVE-2015-4268

Produtos afetados

Cisco Identity Services Engine