An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each case, an authenticated administrative user of any type could exploit this vulnerability to gain access to "appadmin" credentials, leading to complete cluster compromise. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hpe

Published: 2018-12-07T21:00:00

Updated: 2018-12-07T20:57:01

Reserved: 2018-02-15T00:00:00


Link: CVE-2018-7065

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-12-07T21:29:01.187

Modified: 2019-02-05T19:32:05.137


Link: CVE-2018-7065

JSON object: View

cve-icon Redhat Information

No data.

CWE