Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of these vulnerabilities allow an attacker to complete state-changing actions in the web-based management interface that should not be allowed by their current level of authorization on the platform.
2023-10-25T18:17:31.990
2024-11-21T08:24:10.990
Modified
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arubanetworks | clearpass_policy_manager | < 6.9.13 | Yes |
Application | arubanetworks | clearpass_policy_manager | < 6.10.8 | Yes |
Application | arubanetworks | clearpass_policy_manager | ≤ 6.11.4 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.9.13 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.9.13 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.9.13 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.10.8 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.10.8 | Yes |
Application | arubanetworks | clearpass_policy_manager | 6.10.8 | Yes |