cisco-sa-ISE-XSS-bL4VTML: Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.This vulnerability exists because the
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ISE-XSS-bL4VTML?
The severity of cisco-sa-ISE-XSS-bL4VTML is rated as high due to the potential for stored cross-site scripting attacks.
How do I fix cisco-sa-ISE-XSS-bL4VTML?
To fix cisco-sa-ISE-XSS-bL4VTML, upgrade to the latest version of Cisco Identity Services Engine that addresses this vulnerability.
Who is affected by cisco-sa-ISE-XSS-bL4VTML?
Cisco Identity Services Engine users who have the web-based management interface are affected by cisco-sa-ISE-XSS-bL4VTML.
What can an attacker do with cisco-sa-ISE-XSS-bL4VTML?
An attacker can perform a stored cross-site scripting attack, potentially gaining access to sensitive user data.
Is authentication required to exploit cisco-sa-ISE-XSS-bL4VTML?
Yes, an attacker must be authenticated to exploit the cisco-sa-ISE-XSS-bL4VTML vulnerability.