cisco-sa-ise-xxe-jWSbSDKt: Cisco Identity Services Engine XML External Entity Processing Information Disclosure Vulnerability
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information. This vulnerability is
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ise-xxe-jWSbSDKt?
The severity of cisco-sa-ise-xxe-jWSbSDKt is considered critical due to the potential unauthorized access to sensitive information by an authenticated attacker.
How do I fix cisco-sa-ise-xxe-jWSbSDKt?
To fix cisco-sa-ise-xxe-jWSbSDKt, update your Cisco Identity Services Engine and Cisco ISE Passive Identity Connector to the latest patched version.
Who is affected by cisco-sa-ise-xxe-jWSbSDKt?
Cisco Identity Services Engine and Cisco ISE Passive Identity Connector users are affected by cisco-sa-ise-xxe-jWSbSDKt.
What types of attacks can cisco-sa-ise-xxe-jWSbSDKt enable?
cisco-sa-ise-xxe-jWSbSDKt can enable authenticated remote attackers to access sensitive information stored within the system.
Is administrative access required to exploit cisco-sa-ise-xxe-jWSbSDKt?
Yes, administrative access is required for an attacker to exploit cisco-sa-ise-xxe-jWSbSDKt.