CVE-2015-0757
published 2015-05-29CVE-2015-0757: The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.47%
82.6th percentile
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| glance_project | glance | >= 0 < 1:2014.1.5-0ubuntu1.1 | 1:2014.1.5-0ubuntu1.1 |
| glance_project | glance | >= 11.0.0 < 11.0.2 | 11.0.2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_cisco5.0MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9f58-w643-6379: The web framework in Cisco Identity Services Engine (ISE) 1
ghsa_unreviewed·2022-05-17
CVE-2015-0757 [MEDIUM] CWE-200 GHSA-9f58-w643-6379: The web framework in Cisco Identity Services Engine (ISE) 1
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.
GHSA
OpenStack Image Service (Glance) vulnerable to Improper Access Control
ghsa·2022-05-17
CVE-2016-0757 [MEDIUM] CWE-284 OpenStack Image Service (Glance) vulnerable to Improper Access Control
OpenStack Image Service (Glance) vulnerable to Improper Access Control
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.
OSV
glance vulnerabilities
osv·2017-10-11·CVSS 5.5
CVE-2015-5251 glance vulnerabilities
glance vulnerabilities
Hemanth Makkapati discovered that OpenStack Glance incorrectly handled
access restrictions. A remote authenticated user could use this issue to
change the status of images, contrary to access restrictions.
(CVE-2015-5251)
Mike Fedosin and Alexei Galkin discovered that OpenStack Glance incorrectly
handled the storage quota. A remote authenticated user could use this issue
to consume disk resources, leading to a denial of service. (CVE-2015-5286)
Erno Kuvaja discovered that OpenStack Glance incorrectly handled the
show_multiple_locations option. When show_multiple_locations is enabled,
a remote authenticated user could change an image status and upload new
image data. (CVE-2016-0757)
Red Hat
openstack-glance: Glance image status manipulation through locations
vendor_redhat·2016-02-04·CVSS 4.3
CVE-2016-0757 [MEDIUM] CWE-285 openstack-glance: Glance image status manipulation through locations
openstack-glance: Glance image status manipulation through locations
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.
An authorization vulnerability in OpenStack Image service was discovered, which allowed image-status manipulation using locations. By removing the last location of an image, an authenticated user could change the status from 'active' to 'queue'. A malicious tenant could exploit this flaw to silently replace owned image data, regardless of its original creator or visibility settings. Only environments with show_multiple_locations set to true (not default) were affecte
Cisco
Cisco Identity Services Engine Information Disclosure Vulnerability
vendor_cisco·2015-05-27·CVSS 5.0
CVE-2015-0757 [MEDIUM] CWE-200 Cisco Identity Services Engine Information Disclosure Vulnerability
Cisco Identity Services Engine Information Disclosure Vulnerability
A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access information on a targeted device that is normally available only to authenticated users.
The vulnerability is due to improper implementation of session handlers set on an affected device. An attacker could exploit this vulnerability by accessing the affected web pages on a targeted device. A successful exploit could allow the attacker to gain access to sensitive information, such as reports generated by the MnT component, which could be leveraged to conduct further attacks.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker m
No detection rules found.
No writeups or analysis indexed.
2015-05-29
Published