PT-2018-17880 · Aruba · Aruba Clearpass Policy Manager

Publicado

2018-12-07

·

Atualizado

2019-02-05

·

CVE-2018-7065

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aruba ClearPass Policy Manager versions prior to 6.7.6 Aruba ClearPass Policy Manager versions prior to 6.6.10-hotfix
Description An authenticated SQL injection issue in Aruba ClearPass Policy Manager can lead to privilege escalation. This allows an authenticated administrative user to gain access to appadmin credentials, resulting in complete cluster compromise.
Recommendations For versions prior to 6.7.6, update to version 6.7.6 to resolve the issue. For versions prior to 6.6.10-hotfix, apply the 6.6.10-hotfix to resolve the issue.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7065

Produtos afetados

Aruba Clearpass Policy Manager