The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8015 | vendor advisory |
http://www.securitytracker.com/id/1031423 | vdb entry |