PT-2015-3184 · Cisco · Cisco Identity Services Engine
Published
2015-07-14
·
Updated
2016-12-28
·
CVE-2015-4268
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine versions 1.2(1.198) and 1.3(0.876)
Description
The issue exists due to insufficient protection of the web page structure, allowing for the exploitation of multiple cross-site scripting (XSS) vulnerabilities. This can enable a remote attacker to inject arbitrary web script or HTML code via
GET or POST requests.Recommendations
For version 1.2(1.198), update to a version that includes the fix for Bug ID CSCus16052.
For version 1.3(0.876), update to a version that includes the fix for Bug ID CSCus16052.
As a temporary workaround, consider restricting access to the Infra Admin UI to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Identity Services Engine