Cisco Secure Access Control Server Multiple Vulnerabilities
Description
(#Several vulnerabilities were reported in Cisco Secure Access Control Server:#- CVE-2015-6346: DOM cross-site scripting##- CVE-2015-6347: security bypass allowing an authenticated remote attacker to impact integrity of the system by modifying dashboard portlets that should be restricted. This vulnerability stems from improper role-based access control (RBAC) validation when a new administrative dashboard or portlet is created##- CVE-2015-6349: cross-site scripting.##Cisco announces that private exploitation codes exists for these vulnerabilities.)
Vulnerable Products
Vulnerable Software: Secure Access Control Server (ACS) (Cisco) - 5.7(0.15)