First published: Fri May 29 2015(Updated: )
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine Software | =1.2\(1.901\) | |
Cisco Identity Services Engine Software | =1.3\(0.722\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.