Vulnerabilities (CVE)

Filtered by vendor Arubanetworks Subscribe
Filtered by product Clearpass
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-29145 1 Arubanetworks 1 Clearpass 2021-05-10 7.5 HIGH 9.8 CRITICAL
A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.
CVE-2020-7114 1 Arubanetworks 1 Clearpass 2020-04-23 7.5 HIGH 9.8 CRITICAL
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this attack, a possible complete cluster compromise might occur. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.
CVE-2016-4401 1 Arubanetworks 1 Clearpass 2019-11-08 10.0 HIGH 9.8 CRITICAL
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
CVE-2016-2034 1 Arubanetworks 1 Clearpass 2017-06-14 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.