SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCul21337.
| Software | From | Fixed in |
|---|---|---|
| cisco / identity_services_engine_software | 1.1 | 1.1.x |
| cisco / identity_services_engine_software | 1.0 | 1.0.x |
| cisco / identity_services_engine_software | - | 1.2.x |