A remote authenticated server-side request forgery (ssrf) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manage that address this security vulnerability.
2022-05-16T21:15:07.983
2024-11-21T06:49:03.500
Modified
CVSSv3.1: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arubanetworks | clearpass_policy_manager | < 6.8.9 | Yes |
Application | arubanetworks | clearpass_policy_manager | < 6.9.10 | Yes |
Application | arubanetworks | clearpass_policy_manager | < 6.10.5 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.8.9 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.8.9 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.8.9 | Yes |