First published: Mon Dec 22 2014(Updated: )
The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8015 has been assigned a medium severity rating due to its potential to expose guest accounts to unauthorized access.
To mitigate CVE-2014-8015, update your Cisco Identity Services Engine to the latest version as recommended by Cisco.
CVE-2014-8015 affects remote authenticated users of the Cisco Identity Services Engine who can exploit the vulnerability to access guest accounts.
CVE-2014-8015 is a security vulnerability related to improper validation of HTTP requests in the Sponsor Portal of Cisco Identity Services Engine.
CVE-2014-8015 impacts installations of Cisco Identity Services Engine software.