Intrusion Prevention

Cisco.Identity.Services.Engine.LiveLogSettingsServlet.XSS

Description

This indicates an attack attempt on a Cross-Site Scripting (XSS) vulnerability in Cisco Identity Services Engine.
A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted request to the target server. Successful exploitation results in the execution of arbitrary script code in the browser.

Affected Products

Cisco Systems Identity Services Engine 2.2 prior to (0.913)

Impact

System Compromise : Remote attackers can execute arbitrary script code within the context of the target user's browser

Recommended Actions

Refer to the vendor supplied advisory for updates:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-ise-multi-xss

CVE References

CVE-2018-15440