PT-2021-21830 · Aruba · Aruba Airwave Management Platform
Published
2021-08-26
·
Updated
2021-09-07
·
CVE-2021-37715
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Aruba AirWave Management Platform versions prior to 8.2.13.0
Description:
A remote cross-site scripting (XSS) vulnerability was discovered in the Aruba AirWave Management Platform. This issue allows for the execution of malicious scripts on the client-side, potentially leading to unauthorized access or data theft. Aruba has released upgrades that address this security vulnerability.
Recommendations:
For versions prior to 8.2.13.0, upgrade to version 8.2.13.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the platform until the upgrade can be applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aruba Airwave Management Platform