CVE-2016-1485: XSS
Published Aug 22, 2016
·Updated
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva46497.
Affected Software
1 affected component
Cisco Identity Services Engine Software=1.3\(0.876\)
Event History
Aug 22, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1485?
CVE-2016-1485 is considered to be of medium severity due to its cross-site scripting nature.
2
How do I fix CVE-2016-1485?
To fix CVE-2016-1485, upgrade Cisco Identity Services Engine to a version that is not vulnerable, such as later than 1.3(0.876).
3
What types of attacks can CVE-2016-1485 allow?
CVE-2016-1485 allows attackers to inject arbitrary web scripts or HTML into the application.
4
Which version of Cisco Identity Services Engine is affected by CVE-2016-1485?
CVE-2016-1485 affects Cisco Identity Services Engine version 1.3(0.876) specifically.
5
Is CVE-2016-1485 a local or remote vulnerability?
CVE-2016-1485 is a remote vulnerability, allowing attackers to exploit it over the network.