// For flags

CVE-2018-7065

 

Severity Score

7.2
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each case, an authenticated administrative user of any type could exploit this vulnerability to gain access to "appadmin" credentials, leading to complete cluster compromise. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.

Una vulnerabilidad de inyección SQL autenticada en Aruba ClearPass Policy Manager puede conducir al escalado de privilegios. Todas las versiones de ClearPass se han visto afectadas por múltiples vulnerabilidades de inyección SQL. En cada caso, un usuario autenticado administrativo de cualquier tipo podría explotar esta vulnerabilidad para obtener acceso a las credenciales "appadmin", lo que conduce al compromiso total del clúster. Solución: solucionado en 6.7.6 y 6.6.10-hotfix.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-02-15 CVE Reserved
  • 2018-12-07 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arubanetworks
Search vendor "Arubanetworks"
Clearpass Policy Manager
Search vendor "Arubanetworks" for product "Clearpass Policy Manager"
< 6.6.10
Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " < 6.6.10"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Clearpass Policy Manager
Search vendor "Arubanetworks" for product "Clearpass Policy Manager"
>= 6.7.0 < 6.7.6
Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " >= 6.7.0 < 6.7.6"
-
Affected