A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the improper validation of requests stored in the system's logging database. An attacker could exploit this vulnerability by sending malicious requests to the targeted system. An exploit could allow the attacker to conduct cross-site scripting attacks when an administrator views the logs in the Admin Portal.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2019-01-23T22:00:00Z
Updated: 2024-11-21T19:48:16.369Z
Reserved: 2018-08-17T00:00:00
Link: CVE-2018-15455
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-05T09:54:03.400Z
 NVD
                        NVD
                    Status : Modified
Published: 2019-01-23T22:29:00.400
Modified: 2024-11-21T03:50:50.500
Link: CVE-2018-15455
 Redhat
                        Redhat
                    No data.