PT-2018-17894 · Aruba · Aruba Clearpass Policy Manager
Published
2018-12-07
·
Updated
2019-10-03
·
CVE-2018-7079
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aruba ClearPass Policy Manager versions prior to 6.7.6
Aruba ClearPass Policy Manager versions prior to 6.6.10-hotfix
Description
The issue concerns a guest authorization failure in Aruba ClearPass Policy Manager. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules. This allows any authenticated administrative user to execute those operations regardless of privilege level, potentially enabling low-privilege users to view, modify, or delete guest users.
Recommendations
For versions prior to 6.7.6, update to version 6.7.6 to resolve the issue.
For versions prior to 6.6.10-hotfix, apply the 6.6.10-hotfix to resolve the issue.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aruba Clearpass Policy Manager