PT-2018-17894 · Aruba · Aruba Clearpass Policy Manager
Publicado
2018-12-07
·
Atualizado
2019-10-03
·
CVE-2018-7079
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aruba ClearPass Policy Manager versions prior to 6.7.6
Aruba ClearPass Policy Manager versions prior to 6.6.10-hotfix
Description
The issue concerns a guest authorization failure in Aruba ClearPass Policy Manager. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules. This allows any authenticated administrative user to execute those operations regardless of privilege level, potentially enabling low-privilege users to view, modify, or delete guest users.
Recommendations
For versions prior to 6.7.6, update to version 6.7.6 to resolve the issue.
For versions prior to 6.6.10-hotfix, apply the 6.6.10-hotfix to resolve the issue.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aruba Clearpass Policy Manager