Cisco Identity Services Engine... Note

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

Multiple vulnerabilities exist in Cisco Identity Services Engine and its Passive Identity Connector. These flaws allow authenticated, remote attackers to perform SQL or HQL injection attacks. The vulnerabilities stem from inadequate validation of user input in affected APIs. This oversight allows attackers to craft malicious requests to the device. A successful exploit enables the attacker to execute arbitrary database queries. This, in turn, could lead to unauthorized viewing or modification of sensitive data. Exploiting these vulnerabilities requires the attacker to possess valid administrative credentials. Cisco has addressed these issues by releasing software updates. No workarounds are available to mitigate these specific vulnerabilities. Users are advised to apply the provided software updates to secure their systems.