First published: Thu Nov 03 2016(Updated: )
A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSCva46542. Known Affected Releases: 1.3(0.876).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine (ISE) | =1.3\(0.876\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6453 is classified as a high-severity vulnerability due to its potential for SQL command execution.
To fix CVE-2016-6453, upgrade your Cisco Identity Services Engine to a patched version that addresses this vulnerability.
CVE-2016-6453 specifically affects Cisco Identity Services Engine version 1.3(0.876).
An authenticated, remote attacker can exploit CVE-2016-6453 to execute arbitrary SQL commands.
CVE-2016-6453 is a SQL injection vulnerability within the web framework code of Cisco Identity Services Engine.