CVE-2014-6626
https://notcve.org/view.php?id=CVE-2014-6626
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors. Aruba Networks ClearPass anterior a 6.3.6 y 6.4.x anterior a 6.4.1 no restringe correctamente el acceso a funciones administrativas sin especificar, lo que permite a atacantes remotos evadir la autenticación y ejecutar acciones administrativas a través de vectores desconocidos • http://secunia.com/advisories/61916 http://www.arubanetworks.com/support/alerts/aid-10282014.txt • CWE-284: Improper Access Control •
CVE-2014-6622
https://notcve.org/view.php?id=CVE-2014-6622
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors. Aruba Networks ClearPass anterior a 6.3.6 y 6.4.x anterior a 6.4.1 permite a atacantes remotos determinar la validación de nombres de archivo a través de vectores no especificados. • http://secunia.com/advisories/61916 http://www.arubanetworks.com/support/alerts/aid-10282014.txt • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-6624
https://notcve.org/view.php?id=CVE-2014-6624
The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unspecified vectors. El módulo Insight en Aruba Networks ClearPass anterior a 6.3.6 y 6.4.x anterior a 6.4.1 permite a usuarios remotos autenticados leer ficheros arbitrarios a través de vectores no especificados. • http://secunia.com/advisories/61916 http://www.arubanetworks.com/support/alerts/aid-10282014.txt http://www.securityfocus.com/bid/71215 https://exchange.xforce.ibmcloud.com/vulnerabilities/98877 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-5342
https://notcve.org/view.php?id=CVE-2014-5342
Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-6627. Aruba Networks ClearPass anterior a 6.3.5 y 6.4.x anterior a 6.4.1 permite a atacantes remotos ejecutar comandos arbitrarios a través de vectores sin especificar, una vulnerabilidad diferente a CVE-2014-6627. • http://secunia.com/advisories/61916 http://www.arubanetworks.com/support/alerts/aid-10282014.txt •
CVE-2014-6623
https://notcve.org/view.php?id=CVE-2014-6623
Cross-site request forgery (CSRF) vulnerability in the Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to hijack the authentication of a logged in user via unspecified vectors. Vulnerabilidad de CSRF en el módulo Insight en Aruba Networks ClearPass anterior a 6.3.6 y 6.4.x anterior a 6.4.1 permite a atacantes remotos secuestrar la autenticación de un usuario que ha iniciado sesión a través de vectores no especificados. • http://secunia.com/advisories/61916 http://www.arubanetworks.com/support/alerts/aid-10282014.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •