CVE-2018-7060

Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arubanetworks:clearpass:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:11

Type Values Removed Values Added
References () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt - Vendor Advisory () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt - Vendor Advisory

Information

Published : 2018-08-06 20:29

Updated : 2024-11-21 04:11


NVD link : CVE-2018-7060

Mitre link : CVE-2018-7060

CVE.ORG link : CVE-2018-7060


JSON object : View

Products Affected

arubanetworks

  • clearpass
CWE
CWE-352

Cross-Site Request Forgery (CSRF)