Vulnerabilities > Arubanetworks > Clearpass > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-04-29 CVE-2021-29141 Unspecified vulnerability in Arubanetworks Clearpass
A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks
6.5
2021-04-29 CVE-2021-29139 Cross-site Scripting vulnerability in Arubanetworks Clearpass
A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-79
4.8
2021-04-29 CVE-2021-29142 Cross-site Scripting vulnerability in Arubanetworks Clearpass
A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-79
4.8
2021-04-29 CVE-2021-29138 Unspecified vulnerability in Arubanetworks Clearpass
A remote disclosure of privileged information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks
6.5
2021-04-29 CVE-2021-29144 Unspecified vulnerability in Arubanetworks Clearpass
A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks
6.5
2021-04-29 CVE-2021-29146 Cross-site Scripting vulnerability in Arubanetworks Clearpass
A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-79
5.4
2020-04-16 CVE-2020-7113 Unspecified vulnerability in Arubanetworks Clearpass
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts.
network
low complexity
arubanetworks
4.9
2020-04-16 CVE-2020-7110 Cross-site Scripting vulnerability in Arubanetworks Clearpass
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack.
network
low complexity
arubanetworks CWE-79
4.8
2018-02-27 CVE-2018-0489 Improper Verification of Cryptographic Signature vulnerability in multiple products
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data.
network
low complexity
shibboleth debian arubanetworks CWE-347
6.5