The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page.
References
Configurations
Information
Published : 2015-10-30 03:59
Updated : 2016-12-07 10:19
NVD link : CVE-2015-6348
Mitre link : CVE-2015-6348
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- secure_access_control_server