T
he guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.
References
Configurations
History
21 Nov 2024, 02:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://tools.cisco.com/security/center/viewAlert.x?alertId=40691 - Vendor Advisory | |
| References | () http://www.securitytracker.com/id/1033405 - |
Information
Published : 2015-08-28 15:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-6266
Mitre link : CVE-2015-6266
CVE.ORG link : CVE-2015-6266
JSON object : View
Products Affected
CWE
CWE-287
Improper Authentication