Page 135 of 2428 results (0.014 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent. Aruba ClearPass, en todas las versiones 6.6.x anteriores a la 6.6.9, se han visto afectadas por una vulnerabilidad de omisión de autenticación para obtener privilegios de administrador en el sistema. La vulnerabilidad solo se expone en interfaces web de ClearPass, incluyendo la administrativa, el portal cautivo invitado y la API. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt • CWE-287: Improper Authentication •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

HPE XP P9000 Command View Advanced Edition Software (CVAE) has local and remote cross site scripting vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr. HPE XP P9000 Command View Advanced Edition (CVAE) tiene una vulnerabilidad de Cross-Site Scripting (XSS) remoto y local, desde la versión 7.0.0-00 hasta antes de la 8.60-00 de DevMgr, TSMgr y RepMgr. • https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03859en_us • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. Se ha identificado una vulnerabilidad de omisión remota de restricciones de seguridad en HPE Moonshot Provisioning Manager en versiones anteriores a la v1.24. • https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03843en_us https://www.tenable.com/security/research/tra-2018-15 • CWE-668: Exposure of Resource to Wrong Sphere •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser. Todas las versiones de Aruba ClearPass anteriores a la 6.6.8 contienen vulnerabilidades de Cross-Site Scripting reflejado. Al explotar esta vulnerabilidad, un atacante que pueda engañar a un usuario administrativo de ClearPass que haya iniciado sesión para que haga clic en un enlace podrá obtener información sensible, como las cookies de sesión o las contraseñas. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-004.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version. HPE ha identificado una vulnerabilidad de ataque de cabecera HOST remota en HPE CentralView Fraud Risk Management en versiones anteriores a la CV 6.1. El problema se ha resuelto en HF16 para HPE CV 6.1 o posteriores. • https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03837en_us • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') •