PT-2019-15259 · Aruba · Cloudvision Portal

Publicado

2019-12-19

·

Atualizado

2020-08-24

·

CVE-2019-18181

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CloudVision Portal versions 2018.1 through 2018.2
Description The issue allows users with read-only permissions to bypass restrictions for certain functionality through API calls in the Configlet Builder modules. This can enable authenticated users with read-only access to perform actions that are otherwise restricted in the graphical user interface.
Recommendations For CloudVision Portal versions 2018.1 through 2018.2, consider restricting access to the Configlet Builder modules until a fix is available. As a temporary workaround, limit the use of CVP API calls to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-18181

Produtos afetados

Cloudvision Portal