PT-2018-17894 · Aruba · Aruba Clearpass Policy Manager

Published

2018-12-07

·

Updated

2019-10-03

·

CVE-2018-7079

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aruba ClearPass Policy Manager versions prior to 6.7.6 Aruba ClearPass Policy Manager versions prior to 6.6.10-hotfix
Description The issue concerns a guest authorization failure in Aruba ClearPass Policy Manager. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules. This allows any authenticated administrative user to execute those operations regardless of privilege level, potentially enabling low-privilege users to view, modify, or delete guest users.
Recommendations For versions prior to 6.7.6, update to version 6.7.6 to resolve the issue. For versions prior to 6.6.10-hotfix, apply the 6.6.10-hotfix to resolve the issue.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7079

Affected Products

Aruba Clearpass Policy Manager