cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
1025
Views
20
Helpful
3
Replies

CSCvn64652 - Cisco Identity Services Engine Cross-Site Scripting Vulnerability - 2

user101111
Level 1
Level 1

The bug report states 2.4(0.908) is a known fixed release, however I'm not seeing this patch listed in the software download section. The latest available patch is Patch 9 (906). Is this a typo in the bug report or will an updated patch be released?

1 Accepted Solution

Accepted Solutions

This bug was noted as resolved in the Release notes in Ise 2.4(0.357) Patch 8, so patch after that will also include this fix. Such as Patch 8-9, so it looks like a typo. 

ISE 2.4(0.357) Release Notes

 

 

Resolved Caveats in Cisco ISE Release 2.4.0.357- Cumulative Patch 8

The following table lists the resolved caveats in Release 2.4 cumulative patch 8.

Patch 8 might not work with older versions of SPW. MAC users must upgrade their SPW to MACOSXSPWizard 2.2.1.43 or later, and Windows users must upgrade their SPW to WinSPWizard 2.2.1.53 or later.


Note

After the patch is successfully installed, sometimes you may see an alarm indicating that patch installation failed with an error while trying to reboot. This is a false alarm. You can ignore this alarm.


 Caveat ID NumberDescription

CSCvj83362

Include hostname in posture assessment reports

CSCvk34232

Posture remediation files are limited to 50MB

CSCvn35142

ISE 2.3 : Posture report for endpoint by condition not working as expected

CSCvn44171

Network access user with external password cannot be used as ISE admin

CSCvn52886

User name from WMI information is deleted on receiving a DHCP custom syslog for same endpoint

CSCvn55560

ISE 2.3 after applying patch 5 creation of EOB Guest user does not work

CSCvn56648

When individual policy set is reset, other policy set hit counters are reset to 0.

CSCvn58964

ISE 2.4 slow database response with 500 authorization policies

CSCvn60787

Emails are not sent for alarm specific email configuration

CSCvn61139

Smart Licensing agent thread lock causes GUI login delay in ISE 2.2

CSCvn64652

Cisco Identity Services Engine Cross-Site Scripting Vulnerability

View solution in original post

3 Replies 3

This bug was noted as resolved in the Release notes in Ise 2.4(0.357) Patch 8, so patch after that will also include this fix. Such as Patch 8-9, so it looks like a typo. 

ISE 2.4(0.357) Release Notes

 

 

Resolved Caveats in Cisco ISE Release 2.4.0.357- Cumulative Patch 8

The following table lists the resolved caveats in Release 2.4 cumulative patch 8.

Patch 8 might not work with older versions of SPW. MAC users must upgrade their SPW to MACOSXSPWizard 2.2.1.43 or later, and Windows users must upgrade their SPW to WinSPWizard 2.2.1.53 or later.


Note

After the patch is successfully installed, sometimes you may see an alarm indicating that patch installation failed with an error while trying to reboot. This is a false alarm. You can ignore this alarm.


 Caveat ID NumberDescription

CSCvj83362

Include hostname in posture assessment reports

CSCvk34232

Posture remediation files are limited to 50MB

CSCvn35142

ISE 2.3 : Posture report for endpoint by condition not working as expected

CSCvn44171

Network access user with external password cannot be used as ISE admin

CSCvn52886

User name from WMI information is deleted on receiving a DHCP custom syslog for same endpoint

CSCvn55560

ISE 2.3 after applying patch 5 creation of EOB Guest user does not work

CSCvn56648

When individual policy set is reset, other policy set hit counters are reset to 0.

CSCvn58964

ISE 2.4 slow database response with 500 authorization policies

CSCvn60787

Emails are not sent for alarm specific email configuration

CSCvn61139

Smart Licensing agent thread lock causes GUI login delay in ISE 2.2

CSCvn64652

Cisco Identity Services Engine Cross-Site Scripting Vulnerability