Arubanetworks

Clearpass

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 16.04.2020 19:15:34
  • Zuletzt bearbeitet 21.11.2024 05:36:39

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fi...

  • EPSS 2.79%
  • Veröffentlicht 16.04.2020 19:15:34
  • Zuletzt bearbeitet 21.11.2024 05:36:39

A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.

  • EPSS 0.33%
  • Veröffentlicht 16.04.2020 19:15:34
  • Zuletzt bearbeitet 21.11.2024 05:36:38

ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolu...

  • EPSS 0.45%
  • Veröffentlicht 06.11.2019 15:15:10
  • Zuletzt bearbeitet 21.11.2024 02:52:02

Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.

  • EPSS 0.17%
  • Veröffentlicht 06.08.2018 20:29:01
  • Zuletzt bearbeitet 21.11.2024 04:11:35

Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.

  • EPSS 0.24%
  • Veröffentlicht 27.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:20

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonat...

  • EPSS 0.44%
  • Veröffentlicht 08.01.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 02:05:35

Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by a...

  • EPSS 0.91%
  • Veröffentlicht 29.08.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different vulnerability than CVE-2015-3654.

  • EPSS 0.76%
  • Veröffentlicht 29.08.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Admin" privileges via unspecified vectors.

  • EPSS 0.76%
  • Veröffentlicht 29.08.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.