Vulnerability Bulletins

Cisco Identity Services Engine Portal Privilege Elevation Vulnerability

   
Affected software Cisco
 
A vulnerability in the Sponsor Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access guest accounts created from another sponsor account.The vulnerability is due to a failure to restrict guest accounts across sponsors. An attacker could exploit this vulnerability by manipulating an HTTP request prior to submission to the ISE portal. A successful exploit could allow the attacker to access or modify the login and account details of a guest account

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150402-CVE-2014-8015?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Identity%20Services%20Engine%20Portal%20Privilege%20Elevatio