Information disclosure in Cisco Identity Services Engine (ISE) - CVE-2022-20914
Published: August 4, 2022
Cisco Identity Services Engine (ISE)
Cisco Systems, Inc
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the External RESTful Services (ERS) API. A remote administrator can send a specially crafted HTTP request gain unauthorized access to sensitive information on the system.