First published: Thu Jan 15 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity Services Engine allow remote attackers to inject arbitrary web script or HTML via input to unspecified web pages, aka Bug IDs CSCur69835 and CSCur69776.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8022 has a medium severity rating due to the potential impacts of cross-site scripting attacks.
To fix CVE-2014-8022, update to the latest version of Cisco Identity Services Engine that addresses these vulnerabilities.
CVE-2014-8022 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
While there are no officially documented exploits for CVE-2014-8022, the nature of the vulnerability makes it susceptible to exploitation in the wild.
CVE-2014-8022 affects all versions of Cisco Identity Services Engine prior to the security fixes provided in newer releases.