#VU24159 Improper Authorization in Cisco Identity Services Engine (ISE) - CVE-2019-15255
Published: January 9, 2020
Cisco Identity Services Engine (ISE)
Cisco Systems, Inc
Description
The vulnerability allows a remote user to bypass authorization and access sensitive information related to the device.
The vulnerability exists in the web-based management interface due to the affected software fails to sanitize URLs before it handles requests. A remote user can submit a specially crafted URL and gain unauthorized access to sensitive information.