Vulnerability Bulletins |
Cisco Identity Services Engine Portal Privilege Elevation Vulnerability |
|
| Affected software | Cisco |
|
A vulnerability in the Sponsor Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access guest accounts created from another sponsor account.The vulnerability is due to a failure to restrict guest accounts across sponsors. An attacker could exploit this vulnerability by manipulating an HTTP request prior to submission to the ISE portal. A successful exploit could allow the attacker to access or modify the login and account details of a guest account More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150402-CVE-2014-8015?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Identity%20Services%20Engine%20Portal%20Privilege%20Elevatio |
|






