CVE-2023-43507
25.10.2023, 18:17
A vulnerability in the web-based management interface ofClearPass Policy Manager could allow an authenticatedremote attacker to conduct SQL injection attacks againstthe ClearPass Policy Manager instance. An attacker couldexploit this vulnerability to obtain and modify sensitiveinformation in the underlying database potentially leadingto complete compromise of the ClearPass Policy Managercluster.
Vendor | Product | Version |
---|---|---|
arubanetworks | clearpass_policy_manager | 𝑥 < 6.9.13 |
arubanetworks | clearpass_policy_manager | 6.10.0 ≤ 𝑥 < 6.10.8 |
arubanetworks | clearpass_policy_manager | 6.11.0 ≤ 𝑥 ≤ 6.11.4 |
arubanetworks | clearpass_policy_manager | 6.9.13 |
arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_2 |
arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_3 |
arubanetworks | clearpass_policy_manager | 6.10.8 |
arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_2 |
arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_5 |
𝑥
= Vulnerable software versions