Total vulnerabilities in the database
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. At the time of publication, this vulnerability affected Cisco ISE running software releases prior to 2.4.0 Patch 9 and 2.6.0.
Software | From | Fixed in |
---|---|---|
cisco / identity_services_engine | 2.4(0.902) | 2.4(0.902).x |
cisco / identity_services_engine | 2.4.0-patch_2 | 2.4.0-patch_2.x |
cisco / identity_services_engine | 2.4.0-patch_3 | 2.4.0-patch_3.x |
cisco / identity_services_engine | 2.4.0-patch_5 | 2.4.0-patch_5.x |
cisco / identity_services_engine | 2.4.0-patch_6 | 2.4.0-patch_6.x |
cisco / identity_services_engine | 2.4.0-patch_7 | 2.4.0-patch_7.x |
cisco / identity_services_engine | 2.4.0-patch_8 | 2.4.0-patch_8.x |
cisco / identity_services_engine | 2.4.0-patch_1 | 2.4.0-patch_1.x |
cisco / identity_services_engine | - | 2.4.0 |
cisco / identity_services_engine | 2.5(0.225) | 2.5(0.225).x |