Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities

Related Vulnerabilities: CVE-2018-15440   CVE-2018-15463  

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. For more information about these vulnerabilities, see the Details section of this security advisory. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-ise-multi-xss