CVE-2017-3835
published 2017-02-22CVE-2017-3835: A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other…
PriorityP353high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.79%
75.7th percentile
A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL Injection. More Information: CSCvb15627. Known Affected Releases: 1.4(0.908).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine SQL Injection Vulnerability
vendor_cisco·2017-02-15·CVSS 5.4
CVE-2017-3835 [MEDIUM] CWE-89 Cisco Identity Services Engine SQL Injection Vulnerability
Cisco Identity Services Engine SQL Injection Vulnerability
A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users.
The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by using SQL injection techniques in crafted HTTP POST requests to an affected system. A successful exploit could allow the attacker to view or delete notices owned by other users of the system. The notices may contain guest credentials in clear text.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecur
Cisco
Cisco Identity Services Engine SQL Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3835 Cisco Identity Services Engine SQL Injection Vulnerability
CVE-2017-3835: Cisco Identity Services Engine SQL Injection Vulnerability
A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by using SQL injection techniques in crafted HTTP POST requests to an affected system. A successful exploit could allow the attacker to view or delete notices owned by other users of the system. The notices may contain guest credentials in clear text. There are no
CVSS: 3.0
CWE: CWE-89, CWE-89
Bug IDs: CSCvb15627
GHSA
GHSA-x36x-m4vp-4qm4: A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by
ghsa_unreviewed·2022-05-17
CVE-2017-3835 [HIGH] CWE-89 GHSA-x36x-m4vp-4qm4: A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by
A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL Injection. More Information: CSCvb15627. Known Affected Releases: 1.4(0.908).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96249http://www.securitytracker.com/id/1037841https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-isehttp://www.securityfocus.com/bid/96249http://www.securitytracker.com/id/1037841https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-ise
2017-02-22
Published