First published: Wed Dec 14 2016(Updated: )
Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvb86332 CSCvb86760. Known Affected Releases: 2.0(101.130).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | =2.0\(1.130\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9214 is rated as a high severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2016-9214, update your Cisco Identity Services Engine software to the latest version that addresses this vulnerability.
Users of Cisco Identity Services Engine version 2.0(1.130) are affected by CVE-2016-9214.
An attacker exploiting CVE-2016-9214 could conduct an unauthenticated cross-site scripting attack against users of the affected web interface.
CVE-2016-9214 was publicly disclosed in December 2016.