First published: Thu Oct 10 2013(Updated: )
SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | <=1.2 | |
Cisco Identity Services Engine | =1.0 | |
Cisco Identity Services Engine | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5525 has a high severity rating due to its ability to allow authenticated users to execute arbitrary SQL commands.
To fix CVE-2013-5525, upgrade to a version later than Cisco Identity Services Engine 1.2.
CVE-2013-5525 affects users of Cisco Identity Services Engine software versions 1.2 and earlier.
CVE-2013-5525 is classified as an SQL injection vulnerability.
Attackers exploiting CVE-2013-5525 can execute arbitrary SQL commands on the affected system.