First published: Wed Feb 22 2017(Updated: )
A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL Injection. More Information: CSCvb15627. Known Affected Releases: 1.4(0.908).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | =1.4\(0.908\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3835 is considered to have a high severity due to its potential for unauthorized access to sensitive user data.
To fix CVE-2017-3835, upgrade Cisco Identity Services Engine to a version that is not affected by this vulnerability.
CVE-2017-3835 is an SQL Injection vulnerability that affects the Cisco Identity Services Engine's sponsor portal.
Organizations using Cisco Identity Services Engine version 1.4(0.908) are affected by CVE-2017-3835.
Yes, CVE-2017-3835 can be exploited by an authenticated remote attacker.