cisco-sa-ise-xss-V2bm9JCY: Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. For more information about these vulnerabilities, see
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ise-xss-V2bm9JCY?
The severity of cisco-sa-ise-xss-V2bm9JCY is classified as high because it allows authenticated remote attackers to perform cross-site scripting (XSS) attacks.
How do I fix cisco-sa-ise-xss-V2bm9JCY?
To fix cisco-sa-ise-xss-V2bm9JCY, ensure that you apply the latest security patch provided by Cisco for the Identity Services Engine.
Who is affected by cisco-sa-ise-xss-V2bm9JCY?
Organizations using Cisco Identity Services Engine (ISE) with the vulnerable web-based management interface are affected by cisco-sa-ise-xss-V2bm9JCY.
What are the potential impacts of cisco-sa-ise-xss-V2bm9JCY?
The potential impacts of cisco-sa-ise-xss-V2bm9JCY include unauthorized access to sensitive information and manipulation of web sessions through XSS.
Is user authentication required to exploit cisco-sa-ise-xss-V2bm9JCY?
Yes, user authentication is required to exploit the vulnerabilities noted in cisco-sa-ise-xss-V2bm9JCY.