PT-2026-94013 · Cisco · Cisco Ise Passive Identity Connector+3
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine (ISE) (affected versions not specified)
Cisco ISE Passive Identity Connector (ISE-PIC) (affected versions not specified)
Description
An authenticated remote attacker with valid administrative credentials can perform SQL or HQL (Hibernate Query Language) injection attacks. This issue stems from insufficient validation of user-supplied input sent to affected APIs before the input is used to construct database queries. By sending a crafted request, an attacker can execute arbitrary queries against the underlying database to view or modify unauthorized data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ise Passive Identity Connector
Cisco Identity Services Engine
Identity Services Engine
Identity Services Engine Passive Identity Connector