PT-2018-17880 · Aruba · Aruba Clearpass Policy Manager
Publicado
2018-12-07
·
Atualizado
2019-02-05
·
CVE-2018-7065
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aruba ClearPass Policy Manager versions prior to 6.7.6
Aruba ClearPass Policy Manager versions prior to 6.6.10-hotfix
Description
An authenticated SQL injection issue in Aruba ClearPass Policy Manager can lead to privilege escalation. This allows an authenticated administrative user to gain access to
appadmin credentials, resulting in complete cluster compromise.Recommendations
For versions prior to 6.7.6, update to version 6.7.6 to resolve the issue.
For versions prior to 6.6.10-hotfix, apply the 6.6.10-hotfix to resolve the issue.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aruba Clearpass Policy Manager