Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-41915

Опубликовано: 30 июл. 2024
Источник: nvd
CVSS3: 7.2
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
Версия от 6.11.0 (включая) до 6.11.9 (исключая)
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
Версия от 6.12.0 (включая) до 6.12.2 (исключая)

EPSS

Процентиль: 73%
0.00774
Низкий

7.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
github
больше 1 года назад

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster.

EPSS

Процентиль: 73%
0.00774
Низкий

7.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89