CVE-2015-6266

T

he guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.

Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:identity_services_engine_software:1.2\(0.899\):*:*:*:*:*:*:*

History

21 Nov 2024, 02:34

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/viewAlert.x?alertId=40691 - Vendor Advisory () http://tools.cisco.com/security/center/viewAlert.x?alertId=40691 - Vendor Advisory
References () http://www.securitytracker.com/id/1033405 - () http://www.securitytracker.com/id/1033405 -

Information

Published : 2015-08-28 15:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-6266

Mitre link : CVE-2015-6266

CVE.ORG link : CVE-2015-6266


JSON object : View

CWE
CWE-287

Improper Authentication