PT-2018-8489 · Aruba · Aruba Clearpass

Publicado

2018-08-06

·

Atualizado

2018-10-18

·

CVE-2017-9002

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Aruba ClearPass versions prior to 6.6.8
Description The issue allows an attacker to obtain sensitive information, such as session cookies or passwords, by tricking a logged-in administrative user into clicking a malicious link. This can happen when the administrative user is currently logged into the system in the same browser.
Recommendations For versions prior to 6.6.8, update to version 6.6.8 or later to resolve the issue. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation. Avoid clicking on suspicious links while logged into the ClearPass administrative interface.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9002

Produtos afetados

Aruba Clearpass