PT-2018-17894 · Aruba · Aruba Clearpass Policy Manager

Publicado

2018-12-07

·

Atualizado

2019-10-03

·

CVE-2018-7079

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aruba ClearPass Policy Manager versions prior to 6.7.6 Aruba ClearPass Policy Manager versions prior to 6.6.10-hotfix
Description The issue concerns a guest authorization failure in Aruba ClearPass Policy Manager. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules. This allows any authenticated administrative user to execute those operations regardless of privilege level, potentially enabling low-privilege users to view, modify, or delete guest users.
Recommendations For versions prior to 6.7.6, update to version 6.7.6 to resolve the issue. For versions prior to 6.6.10-hotfix, apply the 6.6.10-hotfix to resolve the issue.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7079

Produtos afetados

Aruba Clearpass Policy Manager