Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2019-12637

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

  • Published: Oct 16, 2019
  • Updated: Apr 13, 2023
  • CVE: CVE-2019-12637
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
cisco / identity_services_engine - 2.3.x
cisco / identity_services_engine 2.4.0.357 2.4.0.357.x
cisco / identity_services_engine 2.4.0.357-patch1 2.4.0.357-patch1.x
cisco / identity_services_engine 2.4.0.357-patch2 2.4.0.357-patch2.x
cisco / identity_services_engine 2.4.0.357-patch3 2.4.0.357-patch3.x
cisco / identity_services_engine 2.4.0.357-patch4 2.4.0.357-patch4.x
cisco / identity_services_engine 2.4.0.357-patch5 2.4.0.357-patch5.x
cisco / identity_services_engine 2.4.0.357-patch6 2.4.0.357-patch6.x
cisco / identity_services_engine 2.4.0.357-patch7 2.4.0.357-patch7.x
cisco / identity_services_engine 2.4.0.357-patch8 2.4.0.357-patch8.x
cisco / identity_services_engine 2.4.0.357-patch9 2.4.0.357-patch9.x
cisco / identity_services_engine 2.3.0.298 2.3.0.298.x
cisco / identity_services_engine 2.3.0.298-patch1 2.3.0.298-patch1.x
cisco / identity_services_engine 2.3.0.298-patch2 2.3.0.298-patch2.x
cisco / identity_services_engine 2.3.0.298-patch3 2.3.0.298-patch3.x
cisco / identity_services_engine 2.3.0.298-patch4 2.3.0.298-patch4.x
cisco / identity_services_engine 2.3.0.298-patch5 2.3.0.298-patch5.x
cisco / identity_services_engine 2.3.0.298-patch6 2.3.0.298-patch6.x