Cisco ACS Solution Engine XSS Vulnerability (CVE-2015-6349)
Cisco ACS Solution Engine XSS Vulnerability (CVE-2015-6349)
Release date:
Updated on:
Affected Systems:
Cisco Access Control Server 5.7 (0.15)
Description:
CVE (CAN) ID: CVE-2015-6349
Cisco Secure Access Control System is an Access policy Control platform.
In Cisco Secure Access Control Server (ACS) 5.7 (0.15), the Solution Engine Web interface has the XSS vulnerability. Remote attackers can construct a URL through, attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151023-acs_xss1
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20151023-acs_xss1) and patches for this:
Cisco-sa-20151023-acs_xss1: Cisco Secure Access Control Server Reflective Cross-Site Scripting Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151023-acs_xss1
This article permanently updates the link address: