CVE-2019-5326

An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:44

Type Values Removed Values Added
References () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-002.txt - Vendor Advisory () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-002.txt - Vendor Advisory

Information

Published : 2020-02-27 17:15

Updated : 2024-11-21 04:44


NVD link : CVE-2019-5326

Mitre link : CVE-2019-5326

CVE.ORG link : CVE-2019-5326


JSON object : View

Products Affected

arubanetworks

  • airwave
CWE
CWE-502

Deserialization of Untrusted Data