Lucene search

K
cvelistHpeCVELIST:CVE-2018-7079
HistoryDec 07, 2018 - 9:00 p.m.

CVE-2018-7079

2018-12-0721:00:00
hpe
www.cve.org
1

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.8%

Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.

CNA Affected

[
  {
    "product": "Aruba ClearPass Policy Manager",
    "vendor": "Hewlett Packard Enterprise",
    "versions": [
      {
        "status": "affected",
        "version": "ClearPass 6.7.x prior to 6.7.6, ClearPass 6.6.10 and earlier without hotfix applied"
      }
    ]
  }
]

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.8%

Related for CVELIST:CVE-2018-7079