CVE-2016-9214
https://notcve.org/view.php?id=CVE-2016-9214
Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvb86332 CSCvb86760. Known Affected Releases: 2.0(101.130). Cisco Identity Services Engine (ISE) contiene una vulnerabilidad que podría permitir a un atacante remoto no autenticado llevar a cabo un ataque de XSS contra el usuario de la interfaz web del sistema afectado. Más Información: CSCvb86332 CSCvb86760. • http://www.securityfocus.com/bid/94807 http://www.securitytracker.com/id/1037417 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ise1 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-9198
https://notcve.org/view.php?id=CVE-2016-9198
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199). Una vulnerabilidad en el componente de integración Active Directory de Cisco Identity Services Engine (ISE) podría permitir a un atacante remoto no autenticado llevar a cabo un ataque de denegación de servicio (DoS). Más Información: CSCuw15041. • http://www.securityfocus.com/bid/94810 http://www.securitytracker.com/id/1037415 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ise • CWE-399: Resource Management Errors •
CVE-2016-6453
https://notcve.org/view.php?id=CVE-2016-6453
A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSCva46542. Known Affected Releases: 1.3(0.876). Una vulnerabilidad en el código de marco de referencia web de Cisco Identity Services Engine (ISE) podría permitir a un atacante remoto autenticado ejecutar comandos SQL arbitrarios en la base de datos. Más información: CSCva46542. • http://www.securityfocus.com/bid/93897 http://www.securitytracker.com/id/1037109 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-ise • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2016-1485
https://notcve.org/view.php?id=CVE-2016-1485
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva46497. Vulnerabilidad de XSS en Cisco Identity Services Engine 1.3(0.876) permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de parámetros manipulados, también conocido como Bug ID CSCva46497. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-ise http://www.securityfocus.com/bid/92518 http://www.securitytracker.com/id/1036647 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-1402
https://notcve.org/view.php?id=CVE-2016-1402
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815. El componente de integración Active Directory (AD) en Cisco Identity Service Engine (ISE) en versiones anteriores a 1.2.0.899 patch 7, cuando se habilita la autorización para miembros del grupo AD, permite a atacantes remotos provocar una denegación del servicio (fallo de autenticación) a través de una solicitud de autenticación Password Authentication Protocol (PAP) manipulada, también conocido como Bug ID CSCun25815. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160517-ise http://www.securitytracker.com/id/1035946 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-287: Improper Authentication •